podman-container-tools/podman
68.6
Adequate · 24 September 2026
166.7k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is Podman, a daemonless container engine and CLI tool for developing, managing, and running OCI containers and container images. It provides comprehensive lifecycle management for containers, pods, images, volumes, and networks, alongside advanced features like Kubernetes YAML integration, distributed builds via remote farms, and automatic container updates. The system supports both local execution and remote connections through a REST API, with native virtual machine management for macOS and Windows environments.
How it got here
2017–2020 — Podman v6 architecture and API overhaul
113 changes.
This period centered on the comprehensive restructuring of Podman for version 6, introducing a unified CLI command hierarchy, a new v6 REST API, and a rewritten Go client bindings layer. The work also involved significant backend improvements, including switching the default state database to SQLite, implementing pluggable locking mechanisms, and enhancing remote connection and rootless namespace management.
2021–2023 — Podman Machine and Kubernetes integration
67 changes.
This period focused on establishing cross-platform virtual machine management through the new Podman Machine subsystem, supporting QEMU, WSL2, Hyper-V, and Apple Hypervisor. It also introduced comprehensive Kubernetes workflow support via the podman kube command group and Quadlet systemd integration, alongside distributed build capabilities with the podman farm feature.
2024–2026 — Podman machine infrastructure and OCI artifacts
38 changes.
This period focused on significantly expanding Podman machine capabilities, introducing native Apple Silicon support via vfkit and libkrun, standardizing disk image pulling, and enhancing connection and locking mechanisms. Concurrently, the project added comprehensive support for OCI artifact management through new CLI commands and API bindings, while also improving developer tooling with local validation scripts and a migration to GitHub Actions for CI.
Features
API server idle timeout tracking for non-remote builds
The API server now includes an idle tracker (available in non-remote builds) that monitors HTTP connection states to detect when the server has no active connections. When all connections close, a timer starts; if no new activity occurs within the configured duration, the server signals that it is idle. This mechanism allows the server to automatically shut down or take other actions after a period of inactivity, improving resource efficiency for standalone deployments.
pkg/api/server/idle · high confidence
Add API for communicating with Docker volume plugins
Users can now connect to and use external Docker-compatible volume plugins. This change introduces the \libpod/plugin\ package, which implements the Docker Volume Plugin API (including activation, validation, and reachability checks via Unix sockets) and integrates with the configuration system to support volume plugin timeouts.
libpod/plugin · high confidence
Add FreeBSD-specific rctl account retrieval implementation
Introduces a new \rctl\_freebsd.go\ file that implements the \GetRacct\ function for FreeBSD systems. This function interacts with the OS \rctl\_get\_racct\ syscall to retrieve resource control account data, parsing the resulting string into a map of key-value pairs for use by the \rctl\ package.
pkg/rctl · high confidence
Add Go bindings for Podman secrets management
This change introduces the Go HTTP bindings for managing secrets, providing functions to list, inspect, create, remove, and check the existence of secrets via the Podman API. The bindings support filtering for secret lists, displaying secret data during inspection, and creating secrets with labels, custom drivers, and options to replace or ignore existing entries.
pkg/bindings/secrets · high confidence
Add Go bindings for container auto-update with filtering and rollback support
The \pkg/bindings/auto-update\ package introduces a new Go API for triggering container auto-updates via the Podman API. This binding allows users to configure update behavior through \AutoUpdateOptions\, including the ability to filter which containers are considered for updates, perform dry-run checks, enable rollback on failure, and handle registry authentication and TLS verification settings.
pkg/bindings/auto-update · high confidence
Add Go bindings for generate systemd and generate kube APIs
The \pkg/bindings/generate\ package now exposes Go client functions for the Podman API's \generate systemd\ and \generate kube\ endpoints. Users can programmatically generate systemd unit files (with options for restart policies, timeouts, dependencies, and environment variables) and Kubernetes YAML manifests (supporting Pod/Deployment types, replicas, and annotations) via the \Systemd\ and \Kube\ functions, which handle parameter serialization and response processing.
pkg/bindings/generate · high confidence
Add PowerShell tab-completion for podman and podman-remote
Users on Windows can now enable tab-completion for the \podman\ and \podman-remote\ commands in PowerShell. This change introduces new completion scripts (\podman.ps1\ and \podman-remote.ps1\) that integrate with the shell's native completion engine, allowing users to press Tab to auto-complete commands, flags, and arguments. The scripts handle various completion modes (TabCompleteNext, Complete, MenuComplete) and correctly parse command-line arguments to provide context-aware suggestions.
completions/powershell · high confidence
Add Windows-specific 9P file sharing via Hyper-V Sockets
Users on Windows can now share host directories with Hyper-V virtual machines using the 9P protocol over Hyper-V Sockets (HVSocks). This change introduces Windows-specific implementations (\serve\_windows.go\ and \server\_windows.go\) that listen on predefined vsock GUIDs and expose local directories to the VM. The implementation relies on the \hugelgupf/p9\ library for the 9P server logic and \linuxkit/virtsock\ for socket communication, enabling file sharing capabilities specifically for the Windows build target.
pkg/fileserver · high confidence
Add bash completion scripts for podman and podman-remote
New bash completion scripts have been added for the \podman\ and \podman-remote\ commands, enabling shell tab-completion for subcommands and flags. These scripts implement the Cobra V2 completion protocol, allowing the shell to dynamically query the binaries for available options and arguments, thereby improving the user experience when typing complex commands.
completions/bash · high confidence
Add ctime package for file creation time detection
Introduces a new \pkg/ctime\ utility that provides a \Created\ function to retrieve file creation times. On Linux, it accesses the \st\_ctim\ field from the syscall stat structure, while on unsupported platforms it falls back to the file modification time.
pkg/ctime · high confidence
Add embedded Kubernetes API type definitions
The \pkg/k8s.io/api\ directory now includes the embedded Kubernetes API type definitions (including \LICENSE\, \apps/v1/types.go\, \core/v1/types.go\, and supporting files). This provides the local data structures required for Podman's \kube play\ and \kube generate\ commands to parse and manipulate Kubernetes YAML manifests without relying on external API server interactions.
pkg/k8s.io/api · high confidence
Add emulation package to detect registered binfmt\_misc platforms
The new \pkg/emulation\ package introduces logic to detect which target platforms have user-space emulation registered via the Linux \binfmt\_misc\ subsystem. On Linux, it walks \/proc/sys/fs/binfmt\_misc\ to parse registry entries, matching ELF magic headers against known platform signatures (such as linux/amd64, linux/arm64, etc.) to return a list of available emulated targets. The package includes platform-specific implementations (\binfmtmisc\_linux.go\, \elf.go\) and stubs for non-Linux systems, along with tests to verify the parsing and matching logic.
pkg/emulation · high confidence
Add image scp transfer with compression support and secrets filtering
This change introduces the core logic for the \podman image scp\ command in \pkg/domain/utils\, enabling users to transfer container images between local and remote hosts. The implementation supports optional compression (gzip and zstd) to reduce network bandwidth usage during transfers, handles SSH connections for remote execution, and correctly parses image arguments including usernames containing '@'. Additionally, a new utility function \IfPassesSecretsFilter\ is added to support filtering secrets by name or ID in the HTTP API.
pkg/domain/utils · high confidence
Add libkrun hypervisor support for Apple Silicon machines
Users can now run Podman machines using the libkrun hypervisor on macOS Apple Silicon (darwin/arm64). This change introduces a new \LibKrunStubber\ implementation that configures the virtual machine via the \vfkit\ library, sets up EFI bootloaders, and handles virtiofs mounts and networking. The implementation is specific to the \pkg/machine/libkrun\ package and provides the necessary hooks for VM lifecycle management (create, start, stop, state) and resource configuration for this new provider.
pkg/machine/libkrun · high confidence
Add macOS package installer for Podman
Introduces a new build system in contrib/pkginstaller to generate a macOS .pkg installer. The installer bundles the Podman CLI, gvproxy, vfkit, and krunkit binaries, installing them to /opt/podman. It supports both arm64 and x86\_64 architectures, includes code signing and notarization targets, and provides a standard macOS installation experience with welcome/conclusion screens.
contrib/pkginstaller · high confidence
Add no-op gRPC service for system health checks
A new no-op gRPC responder service has been added to the Podman system service, available on Linux and FreeBSD platforms. This service provides a simple endpoint that accepts requests and returns a response, allowing clients to verify connectivity and basic service availability without triggering any functional operations.
pkg/api/handlers/grpc · high confidence
Add no-op gRPC service to the Podman system API
A new 'Noop' gRPC service has been added to the Podman system service API, defined in \pkg/api/grpcpb\. This service exposes a single unary RPC method that accepts a \NoopRequest\ and returns a \NoopResponse\, effectively acting as a placeholder or health-check endpoint. The implementation includes the Protobuf definition (\noop.proto\) and the generated Go client and server stubs, along with a build script to regenerate these files using \protoc\ and \gofumpt\.
pkg/api/grpcpb · high confidence
Add podman healthcheck run command with --ignore-result flag
Users can now execute health checks on containers using the new 'podman healthcheck run' command. This command supports an '--ignore-result' flag, which allows the process to exit with code 0 regardless of the health check outcome or if the container is still in its startup period, providing more flexible scripting options for container monitoring.
cmd/podman/healthcheck · high confidence
Add podman-docker compatibility scripts to emulate Docker CLI
The package now includes shell scripts (podman-docker.sh, podman-docker.csh) and a wrapper (docker.in) that automatically configure the DOCKER\_HOST environment variable to point to the local podman socket, allowing users to run Docker CLI commands via podman. The scripts handle root vs. non-root user contexts and respect existing DOCKER\_HOST settings, while the wrapper provides a warning message that can be suppressed by creating a nodocker file.
docker · high confidence
Add podman-testing CLI for storage manipulation and GRPC diagnostics
The \podman-testing\ command-line tool is introduced to provide utilities for testing Podman internals. It includes commands to create, populate, modify, and remove layers, images, and containers in local storage (available on Linux and FreeBSD), allowing testers to intentionally corrupt or manipulate storage state. Additionally, it provides GRPC diagnostic commands (\noop\ and \ls\) to interact with the Podman system service in remote mode, enabling verification of GRPC endpoints and service reflection.
cmd/podman-testing · high confidence
Add project configuration files for linting, formatting, and CI automation
The repository now includes configuration files for developer tooling and CI automation. A \.golangci.yml\ file configures the golangci-lint suite, enabling formatters (gofumpt, goimports) and a comprehensive set of linters (staticcheck, revive, errcheck, etc.) with specific exclusions and settings. A \.codespellrc\ file configures the codespell tool for spelling checks, defining skip patterns and ignored words. A \.pre-commit-config.yaml\ file sets up pre-commit hooks to enforce code quality standards before commits. Additionally, a \.packit.yaml\ file configures Packit for downstream Fedora/CentOS Stream packaging, defining build targets, test plans (TMT), and release automation jobs. An \.editorconfig\ file standardizes indentation and line endings for shell scripts. These files collectively standardize the development environment and automate quality checks and packaging workflows.
(repo-wide) · high confidence
Add systemd notify proxy for container lifecycle signaling
A new \pkg/systemd/notifyproxy\ package has been introduced to handle systemd-style notification messages (such as \READY\ and file descriptor barriers) via a Unix socket. This component allows the system to proxy these signals to containers, ensuring proper lifecycle synchronization and readiness detection during operations like \kube play\.
pkg/systemd/notifyproxy · high confidence
Add vendored Kubernetes apimachinery library
The \pkg/k8s.io/apimachinery\ directory now includes a vendored copy of the Kubernetes \apimachinery\ library, providing core types and utilities such as \Quantity\ for fixed-point resource values, \Time\ and \Duration\ wrappers for JSON/YAML serialization, and standard metadata structures like \ObjectMeta\ and \TypeMeta\. This addition enables the application to interact with Kubernetes-style API objects and resource specifications directly.
pkg/k8s.io/apimachinery · high confidence
Add vfkit-based Apple Silicon machine support
New helper and REST mapping files are added for the vfkit virtualization backend on macOS, enabling Podman machines to run on Apple Silicon. The code implements communication with the vfkit REST API to query and change virtual machine states (stopped, running, paused, etc.) and provides a graceful stop mechanism that waits up to 90 seconds before issuing a hard stop if the VM does not shut down cleanly.
pkg/machine/apple/vfkit · high confidence
Added dependency analysis tooling for binary bloat checks
A new \contrib/dependencies\ directory now includes a \dependencies.sh\ script and documentation to help analyze Go dependency usage and binary size. The script wraps the \goda\ tool to provide commands for listing packages, viewing dependency trees, identifying importers (\why\), and comparing dependency changes between branches (\diff\). It also supports bloat analysis via \cut\ to find high-impact packages for removal and \weight\ to inspect symbol sizes, aiding developers in reducing the final binary footprint.
contrib/dependencies · high confidence
Added local pre-CI validation script and container environment
Developers can now run a local validation workflow via the new \contrib/validatepr/validatepr.sh\ script, which builds Windows, Darwin, and Linux binaries and runs the project's standard validation tooling (linting, man pages, etc.). A corresponding \Containerfile\ provides a Fedora-based container environment with all necessary build dependencies (Go, Perl, system libraries) to ensure consistent results.
contrib/validatepr · high confidence
Added parallel job execution with thread limiting
A new parallel execution package has been introduced to allow concurrent processing of tasks while strictly limiting the number of active threads. Users can configure the maximum thread count via SetMaxThreads, and tasks are submitted using Enqueue, which returns a channel to receive the result or error once the task completes, ensuring controlled resource usage.
pkg/parallel · high confidence
Added performance benchmarking scripts for container engines
A new set of shell scripts has been added to the \hack/perf\ directory to compare the performance of two container engines (defaulting to Podman and Docker). These scripts use \hyperfine\ to benchmark operations such as creating, starting, stopping, running, and removing containers, as well as listing containers and checking disk usage. The benchmarks are configurable via environment variables for the number of runs, containers, and the image used, and they include cleanup steps to ensure consistent results.
hack/perf · high confidence
Added shell autocompletion support for bash, zsh, fish, and powershell
Users can now generate shell autocompletion scripts for bash, zsh, fish, and powershell using the new completion command. The command supports outputting to a file or stdout, and includes options to control whether descriptions are included in the generated scripts.
cmd/podman/completion · high confidence
Added temporary file management for build operations
The build process now includes a dedicated TempFileManager to handle temporary files created during image builds. This utility ensures that temporary files are automatically tracked and cleaned up after use, preventing resource leaks and ensuring proper resource management during the build lifecycle.
_internal/remote\_build\helpers · high confidence
Added utility to read and parse CA certificate bundles
A new \ReadCertBundle\ function has been added to the \tlsutil\ package, allowing users to load a file containing multiple PEM-encoded X.509 certificates into a single certificate pool. This utility handles reading the file, decoding the PEM blocks, validating that each block is a certificate, and parsing the certificate data, returning an error if the file cannot be read or contains invalid non-certificate PEM data.
pkg/util/tlsutil · high confidence
Automatic proxy configuration for Podman machines
The system now automatically detects host HTTP/HTTPS proxy settings and applies them to all Podman virtual machines. This is achieved by generating and executing a setup script that writes proxy values to systemd environment configuration files (system and user scopes), /etc/environment.d, and /etc/profile.d, ensuring the proxy is available to the VM's services and shell sessions. The implementation includes specific handling for WSL environments, replacing localhost references with the appropriate container hostname, and correctly escapes special characters like percent signs in proxy URLs to prevent systemd parsing errors.
pkg/machine/proxyenv · high confidence
Centralized CLI flag definitions and shell completion logic
The \cmd/podman/common\ package now provides shared infrastructure for the Podman CLI, consolidating flag definitions and shell completion logic previously scattered across command-specific files. This change introduces dedicated modules for build options (\build.go\), container creation defaults and flags (\create.go\, \create\_opts.go\), network configuration (\netflags.go\), and image signing (\sign.go\). It also adds a comprehensive shell completion engine (\completion.go\) that supports dynamic suggestions for containers, pods, and Go template formatting, along with corresponding tests (\completion\_test.go\, \create\_test.go\). For users, this ensures consistent flag behavior and improved autocomplete accuracy across \podman build\, \podman create\, \podman run\, and related commands.
cmd/podman/common · high confidence
Go bindings for Podman artifact management
The Go bindings in pkg/bindings/artifacts now provide a complete client API for managing container artifacts. Users can add artifacts (including local files and with replace/append options), pull and push artifacts to registries with authentication, list and inspect artifacts, and remove them (including bulk removal and ignoring errors). The extract function allows retrieving artifact blobs to the local filesystem, with safety checks to prevent path traversal and handling of single vs. multiple blob artifacts.
pkg/bindings/artifacts · high confidence
Import host CA certificates into Podman machines
Podman machines now automatically import trusted CA certificates from the host operating system into the guest machine's trust store. This ensures that containers running inside the machine can verify TLS connections to private or custom certificate authorities without manual configuration. The implementation adds a new \certificates\ package that extracts host certificates on macOS (via keychains), Linux/FreeBSD (via system bundles and environment variables), and Windows (via certificate stores), and transfers them to the guest's anchor folder to update the system trust list.
pkg/machine/e2e · high confidence
Initial Apple Hypervisor (AppleHV) machine provider implementation
Adds the initial implementation of the Apple Hypervisor provider for Podman machines on macOS, enabling users to run Linux virtual machines using Apple's native hypervisor framework via the vfkit tool. This change introduces the core machine lifecycle management (create, start, stop, remove, state) and networking setup specific to AppleHV, including support for virtiofs volume mounts and Rosetta emulation on Apple Silicon (arm64) architectures.
pkg/machine/applehv · high confidence
Initial implementation of Podman Quadlet systemd integration
This change introduces the \pkg/systemd/quadlet\ package, enabling Podman to generate systemd unit files from declarative \.container\, \.pod\, \.volume\, \.network\, \.kube\, \.image\, \.build\, and \.artifact\ files. It establishes the core infrastructure for locating these unit files in standard directories (such as \/etc/containers/systemd\ and \$XDG\_CONFIG\_HOME/containers/systemd\), parsing their configuration keys, and constructing the corresponding \podman\ command lines. This allows users to manage containers and pods as native systemd services.
pkg/systemd/quadlet · high confidence
Initial support for Podman machines on Windows via WSL2
Adds a new WSL2-based implementation for Podman machines on Windows, enabling users to create, start, and manage virtual machines using the Windows Subsystem for Linux. This change introduces core infrastructure including WSL distribution provisioning, SSH key management, and systemd configuration within the guest. It also implements user-mode networking to allow container network access without requiring Hyper-V, along with API forwarding and socket binding to connect the Windows host to the WSL-based Podman daemon. The feature includes automatic installation checks, reboot handling for WSL feature enablement, and file locking for state persistence.
pkg/machine/wsl · high confidence
Introduce Apple (AppleHypervisor/libkrun) VM provider implementation
This change adds the core implementation for running Podman machines on macOS using the Apple Hypervisor framework (via vfkit and libkrun). The new \pkg/machine/apple\ package handles VM lifecycle management, including starting the VM with virtio-net networking, virtio-blk storage, and virtio-fs mounts. It introduces support for injecting Ignition configuration files during the first boot via a vsock HTTP server, enables nested virtualization when using the libkrun hypervisor, and adds optional Rosetta 2 support for running x86\_64 binaries on Apple Silicon. The implementation also includes a local copy of vfkit REST endpoint parsing to avoid heavy external dependencies and supports debug consoles for the libkrun provider.
pkg/machine/apple · high confidence
Introduce Go bindings for kube play, down, apply, and generate commands
This change adds the \pkg/bindings/kube\ package, providing the Go client-side bindings for the Podman Kubernetes integration. It implements HTTP client functions for \Play\ (POST \/play/kube\), \Down\ (DELETE \/play/kube\), \Apply\ (POST \/kube/apply\), and \Generate\, allowing remote clients to interact with these Kubernetes features. The bindings include detailed option structs (\PlayOptions\, \ApplyOptions\, \DownOptions\) that support features such as configuring port publishing (\PublishPorts\, \PublishAllPorts\), handling ConfigMaps, managing authentication (\Authfile\, \Username\, \Password\), and controlling pod lifecycle (\Start\, \Replace\, \Wait\).
pkg/bindings/kube · high confidence
Introduce Go-based podman-registry helper for test infrastructure
Added a new Go module at hack/podman-registry-go that provides a Registry struct and StartWithOptions/Stop methods to programmatically manage local container registries for testing. The implementation invokes the podman-registry binary via utils.ExecCmd, parses environment-based output (image, user, password, port), and includes tests verifying the lifecycle of multiple concurrent registries.
hack/podman-registry-go · high confidence
Introduce PIDHandle to prevent accidental signal delivery to recycled processes
Added a new \pkg/pidhandle\ package that provides a \PIDHandle\ interface for safely interacting with operating system processes. This new component mitigates the risk of accidentally sending signals (such as \Kill\ or \KillProcessGroup\) to a different process if the original process has exited and its PID has been reused by the system. On Linux, it leverages \pidfd\ and \name\_to\_handle\ APIs for robust identity verification, falling back to process start-time checks on other Unix systems or when \pidfd\ is unavailable.
pkg/pidhandle · high confidence
Introduce Podman Machine with cross-platform hypervisor support
This change introduces the \podman machine\ subsystem, enabling the creation and management of lightweight virtual machines to run the Podman API. It adds a new \pkg/machine\ package that implements a provider-agnostic interface for VM lifecycle management (init, start, stop, inspect, reset) and includes initial implementations for QEMU, Hyper-V, Apple Hypervisor (AppleHV), and Windows Subsystem for Linux (WSL). The update adds cross-platform process management for the \gvproxy\ helper, SSH key generation, and port allocation logic, along with support for virtiofs volume mounts and API socket forwarding on Windows and Unix systems.
pkg/machine · high confidence
Introduce \`podman artifact\` CLI for OCI artifact management
Adds a new \podman artifact\ command group to manage OCI artifacts, including \add\ (with options to set annotations, MIME types, and append/replace behavior), \ls\ (listing with columns for digest, size, and creation time, plus \--format\, \--quiet\, and \--no-trunc\ flags), \inspect\ (with \--format\ for JSON or Go templates), \pull\ and \push\ (supporting authentication, TLS verification, and retry logic), \extract\ (to retrieve blobs by digest or title), and \rm\ (with \--all\ and \--ignore\ options).
cmd/podman/artifact · high confidence
Introduce bootc-based OS apply and upgrade for Podman machines
Users can now apply and upgrade the operating system of a Podman machine using the bootc toolchain. The new \pkg/machine/os\ package implements an \Apply\ operation that switches the machine's OS image via \bootc switch\ (supporting registry, OCI, and OCI-archive transports) and an \Upgrade\ operation that checks for in-band updates or switches to a specific version via \bootc upgrade\/\switch\. The implementation includes logic to compare client and machine versions, detect available updates by comparing image digests, and optionally restart the machine after applying changes.
pkg/machine/os · high confidence
Introduce dedicated ignition configuration package for Podman machines
Added a new \pkg/machine/ignition\ package that centralizes the generation of Ignition configuration files and systemd units for Podman virtual machines. This change introduces platform-specific timezone detection logic (Linux, macOS, FreeBSD, Windows) to correctly configure the machine's local time, and provides a \CreateReadyUnitFile\ function that generates provider-specific systemd units (for QEMU, Apple Hypervisor, LibKrun, and Hyper-V) to signal when the guest machine has successfully booted. The package also includes the necessary Go structs to represent the Ignition v3.2.0 schema for users, storage, and systemd configuration.
pkg/machine/ignition · high confidence
Introduce file-based locking mechanism for libpod
A new file-based lock implementation has been added to libpod, allowing containers and pods to use filesystem locks for synchronization. This change introduces the \CreateFileLock\, \OpenFileLock\, \AllocateLock\, \LockFileLock\, and \UnlockFileLock\ APIs, which manage lock files within a specified directory. The implementation uses standard file operations and the \lockfile\ package to ensure thread-safe access, providing an alternative to shared-memory locking strategies.
libpod/lock/file · high confidence
Introduce play bindings package
Added a new \pkg/bindings/play\ package that exposes Go bindings for the \play kube\ and \play kube down\ operations. This package acts as a thin wrapper around the underlying \kube\ package, providing \Kube\, \KubeWithBody\, \Down\, and \DownWithBody\ functions to allow other parts of the codebase to interact with the play kube API endpoints.
pkg/bindings/play · high confidence
Introduce pluggable lock manager backends (SHM, file, in-memory)
The libpod lock subsystem now supports multiple backend implementations via a unified \Manager\ interface. On Linux, the default shared-memory (SHM) backend uses POSIX semaphores for multiprocess synchronization, while a file-based backend is available for systems without SHM support. An in-memory lock manager is also provided, explicitly intended for unit and integration testing rather than production use. This change allows the runtime to select the appropriate locking mechanism based on the environment and testing requirements.
libpod/lock · high confidence
Introduce pod management subcommands
The \podman pod\ command group is now available, providing a full suite of subcommands for managing pods and their containers. Users can now create, inspect, list, start, stop, pause, unpause, restart, kill, and remove pods, as well as view their logs, top processes, and resource usage statistics. New capabilities include cloning existing pods (\podman pod clone\), pruning stopped pods (\podman pod prune\), and checking for pod existence (\podman pod exists\). The \podman pod ps\ command supports filtering, sorting, and custom formatting, while \podman pod logs\ allows filtering by container and displaying timestamps or colors.
cmd/podman/pods · high confidence
Introduce podman farm build command for distributed image building
This change adds the \pkg/farm\ package, introducing a new \podman farm build\ capability that allows users to distribute image builds across multiple remote builder connections (farm nodes) in addition to the local engine. The implementation handles connecting to remote builders via tunnel mode, inspecting their native and emulated platforms to schedule builds optimally, assembling the resulting images into a manifest list, and pushing the final multi-architecture image to a registry. It also supports outputting the manifest list ID to files via \--iidfile\ and \--iidfile-raw\ flags, and can clean up intermediate images on remote nodes after the build completes.
pkg/farm · high confidence
Introduce podman farm subcommand for distributed builds
Adds the \podman farm\ command group, enabling users to manage and execute container builds across multiple remote machines. The new subcommands include \create\ and \remove\ for managing farm definitions, \list\ for viewing available farms with support for quiet and JSON output formats, and \update\ for modifying farm connections or setting a default farm. The \build\ subcommand allows users to distribute image builds to farm nodes, supporting multi-platform builds, local fallback, and pushing results to a registry.
cmd/podman/farm · high confidence
Introduce podman machine os apply and upgrade commands
Users can now apply custom OCI images to a Podman Machine's operating system and upgrade the machine OS to newer versions. The new \podman machine os apply\ command allows applying custom layers from a containerized Fedora CoreOS OCI image on top of an existing VM, with an optional \--restart\ flag to reboot the VM after changes. The \podman machine os upgrade\ command enables upgrading the machine OS, supporting \--dry-run\ to check for available upgrades, \--format json\ for structured output, and \--restart\ to reboot the VM. These commands are currently supported on amd64 and arm64 architectures and are not supported for WSL machines.
cmd/podman/machine/os · high confidence
Introduce podman machine subcommand suite
Adds the \podman machine\ command group and its subcommands (\init\, \start\, \stop\, \restart\, \rm\, \list\, \ssh\, \cp\, \info\, \inspect\, \reset\, \set\, \os\), enabling users to manage virtual machines for running Podman. This includes initializing VMs with configurable resources (CPUs, memory, disk), managing their lifecycle, copying files between host and VM, and inspecting machine details.
cmd/podman/machine · high confidence
Introduce podman quadlet CLI for managing systemd quadlet units
Users can now manage systemd quadlet units directly via the new \podman quadlet\ command group. This adds subcommands to install quadlet files or URLs (\install\), list configured quadlets with filtering and formatting options (\list\/\ls\), display raw quadlet contents (\print\/\cat\), and remove installed quadlets (\rm\). The install command supports replacing existing units and grouping them into application directories, while the list command provides detailed status information including associated pods and applications.
cmd/podman/quadlet · high confidence
Introduce podman secret management commands
Adds a new \podman secret\ command group to manage secrets, including \create\ (with support for file, stdin, and environment variable sources, plus \--replace\ and \--ignore\ flags), \exists\ (to check for secret presence), \inspect\ (with \--pretty\ and \--format\ options), \list\ (with filtering and formatting), and \rm\ (with \--all\ and \--ignore\ flags).
cmd/podman/secrets · high confidence
Introduce podman volume management commands
The \podman volume\ command group is now available, providing a complete set of tools for volume lifecycle management. Users can create volumes with specific ownership (\--uid\, \--gid\), drivers, and labels; list and filter volumes; inspect details; and remove or prune unused volumes with \--all\ and \--dry-run\ support. New capabilities include importing and exporting volume contents via tarballs (\import\, \export\), mounting and unmounting volumes directly (\mount\, \unmount\), renaming volumes, checking for existence, and reloading volume plugins to sync the database with available plugins.
cmd/podman/volumes · high confidence
Introduce quadlet systemd generator for container unit files
The \podman quadlet\ command is now available as a systemd generator, allowing users to define containers, pods, networks, and volumes using simple \.container\, \.pod\, \.network\, and \.volume\ files that are automatically converted into systemd units at boot. This feature supports templated units with drop-in overrides, symlinked search paths, and user-specific configurations, providing a native systemd integration for managing containerized workloads.
cmd/quadlet · high confidence
Introduce shared-memory POSIX mutex locking for libpod
Added a new shared-memory (SHM) lock implementation in libpod/lock/shm that uses POSIX robust mutexes to manage container and pod locks across processes. The C backend (shm\_lock.c) and Go bindings (shm\_lock.go) create and manage a shared memory segment containing bitmaps and mutexes, supporting allocation, locking, unlocking, and deallocation of semaphores. The implementation includes robustness features to handle process crashes (EOWNERDEAD) and better error handling for ENOSPC. A stub implementation (shm\_lock\_nocgo.go) is provided for builds without CGO, logging an error and returning no-op results. Tests verify the lock lifecycle, allocation limits, and error conditions.
libpod/lock/shm · high confidence
Introduce standard disk pull implementation for local and remote images
The \pkg/machine/stdpull\ package now provides a standardized mechanism for pulling VM disk images, supporting both local file paths and remote URLs. For local sources, the system verifies file existence and handles decompression. For remote sources, it downloads images via HTTP with a progress bar, optionally caches the temporary download, and then decompresses the result to the final destination.
pkg/machine/stdpull · high confidence
Introduce structured event logging with journald and file backends
Podman now provides a robust, structured event system that replaces the previous memory-based logger. On systemd-enabled Linux systems, events are written to journald by default, while file-based logging is used as a fallback or when systemd is unavailable. The new system supports filtering events by type (container, image, network, volume, pod, secret, artifact, machine, system), status (including new statuses like pull-error, exec\_died, health\_status, and auto-update), and labels. It also introduces time-based filtering (--since, --until), disjunctive filter logic, and ensures concurrency safety with file locking and proper goroutine management to prevent leaks during log rotation or client hangups.
libpod/events · high confidence
Introduce unified 'podman container' subcommand namespace
The \cmd/podman/containers\ package now provides a dedicated \podman container\ command group, exposing subcommands such as \attach\, \checkpoint\, \cleanup\, \clone\, \commit\, \cp\, \create\, \diff\, \exec\, \exists\, \export\, \init\, \inspect\, and \kill\ under this namespace. This change adds the \containerCmd\ parent command and registers the corresponding sub-commands (e.g., \containerAttachCommand\, \containerCreateCommand\) to allow users to manage containers using the explicit \podman container \<action\>\ syntax alongside the existing top-level commands.
cmd/podman/containers · high confidence
Introduces structured shutdown handler management with LIFO execution
Adds a new \libpod/shutdown\ package that centralizes signal handling (SIGINT/SIGTERM) and provides a mechanism to register, unregister, and inhibit shutdown handlers. Users benefit from guaranteed Last-In-First-Out (LIFO) execution order for cleanup routines, ensuring that dependent resources are released in the correct sequence, and the ability to temporarily inhibit shutdown signals during critical operations.
libpod/shutdown · high confidence
Introduction of Podman auto-update functionality for systemd containers
This change introduces the \pkg/autoupdate\ package, enabling automatic updates for containers managed by systemd units. Users can now configure containers to automatically pull and restart with new images based on policies such as \registry\ (checking remote registries) or \local\ (checking local image changes). The implementation supports container-specific authentication files, dry-run modes for validation, and provides detailed status reporting (updated, failed, pending, rolled back) for each container involved in the update process.
pkg/autoupdate · high confidence
Introduction of a pluggable logging interface
A new \logiface\ package provides a \Logger\ interface with \Errorf\ and \Debugf\ methods, along with a global \SetLogger\ function. This allows the application to inject custom logging implementations, enabling users to redirect or customize log output rather than relying on a hardcoded default.
pkg/logiface · high confidence
Introduction of seccomp policy lookup functionality
Added a new \pkg/seccomp\ package that provides logic for resolving seccomp policy strings (such as "default" or "image") into internal policy constants. This includes a \LookupPolicy\ function that validates input against supported policies and returns a descriptive error listing valid options if the input is unrecognized, enabling consistent policy handling for container creation.
pkg/seccomp · high confidence
Introduction of the specgen package for container and pod specification generation
This change introduces the \pkg/specgen\ package, which centralizes the generation and validation of OCI runtime specifications for both containers and pods. It provides \SpecGenerator\ and \PodSpecGenerator\ structs to define configuration, along with dedicated \Validate()\ methods that enforce mutual exclusions (such as \rootfs\ vs \image\, or \NoInfra\ vs network settings) and namespace constraints. The package also includes logic for parsing volume mounts (including overlay and image volumes), handling Windows path conversions, and managing block I/O resource limits on Linux.
pkg/specgen · high confidence
New 'podman generate' command with spec and systemd subcommands
A new top-level 'podman generate' command has been introduced to create structured data from containers, pods, or volumes. It includes a 'spec' subcommand that outputs container/pod specifications as JSON, supporting options to write to a file, compact the output, or assign a new name. It also includes a 'systemd' subcommand that generates systemd unit files for managing containers and pods, featuring flags for timeout overrides, restart policies, environment variables, and dependency definitions; this command is marked as deprecated in favor of Quadlets.
cmd/podman/generate · high confidence
New API handler utility package with version validation and Docker compatibility helpers
A new \apiutil\ package and a set of utility files (containers, images, errors, handler, docker\_device) have been added to \pkg/api/handlers/utils\. This introduces a \SupportedVersion\ function that validates API versions using semver ranges, distinguishing between libpod and compat endpoint trees. It also adds Docker-compatibility helpers, including \WaitContainerDocker\ for handling Docker-style wait conditions and \DockerDeviceMappingString\ for mapping Moby device structures to Podman device strings, alongside standardized error response formatting and JSON writing utilities that disable HTML escaping.
pkg/api/handlers/utils · high confidence
New Docker-compatible REST API endpoints for container management
The compatibility API layer now exposes a comprehensive set of Docker-compatible endpoints for core container operations, including creating, listing, inspecting, starting, stopping, restarting, pausing, exporting, and pruning containers, as well as retrieving logs, stats, and file changes. This implementation adds dedicated handlers for container attachment, archive operations (copying files to/from containers), and authentication, enabling Docker clients to manage Podman containers directly via the standard Docker API without requiring translation or remote-specific workarounds.
pkg/api/handlers/compat · high confidence
New Go bindings for Podman network management
The \pkg/bindings/network\ package now provides a complete Go client for managing Podman networks via the API. This includes functions to create, inspect, list, update, and remove networks, as well as connect and disconnect containers. The bindings support advanced options such as filtering network lists, pruning unused networks, configuring DNS servers, and handling idempotent creation with an ignore flag.
pkg/bindings/network · high confidence
New Go bindings for container operations
The Go bindings package for containers has been completely rewritten to provide a comprehensive API for managing container lifecycles. This update introduces new functions and types for core operations including listing, creating, inspecting, killing, pausing, restarting, and removing containers. It also adds support for advanced features such as container checkpointing and restoration, image committing, health checks, and file archiving (copying to and from containers). Additionally, the bindings now support interactive terminal attachment with proper TTY handling and resizing, remote execution sessions (exec), and streaming container logs.
pkg/bindings/containers · high confidence
New Go bindings for manifest list operations
The \pkg/bindings/manifests\ package now provides a complete Go API for managing manifest lists, including creating, inspecting, adding, removing, and modifying entries. This update introduces support for OCI artifact manifests via the \AddArtifact\ function and allows users to specify authentication files and skip TLS verification during inspection. It also enables setting index-level annotations and subjects, and exposes options to override architecture, OS, and OS features when adding images to a manifest list.
pkg/bindings/manifests · high confidence
New Packit integration scripts for RPM spec handling and dependency updates
Added three new shell scripts in contrib/packit-tmt to support automated RPM builds via Packit. packit-copr-rpm.sh customizes the RPM spec file for Copr builds by updating version, release, and source fields based on the current git HEAD. packit-rpm-git-commit.sh updates the spec file's LDFLAGS with the upstream git SHA for build identification. update-deps.sh provides a safe way to upgrade dependencies via DNF, specifically disabling the testing-farm-tag-repository to avoid conflicts during the upgrade process.
contrib/packit-tmt · high confidence
New Windows MSI installer with user scope and WiX v5 support
The Windows installer has been replaced with a new MSI-based solution built using WiX Toolset v5.0.2, replacing the legacy setup.exe. This new installer supports both 'user' and 'machine' installation scopes, allowing users to install Podman in their local AppData directory or system-wide in Program Files. The build process now explicitly includes gvproxy.exe as a packaged artifact and supports building for both amd64 and arm64 architectures. Automated test scripts have been added to validate installation, updates, and configuration scenarios for both scopes and virtualization providers (WSL and Hyper-V).
contrib/win-installer · high confidence
New Windows installer supports per-user installation scope
A new Windows installer has been introduced that allows Podman to be installed for the current user only (per-user scope), in addition to the existing machine-wide (per-machine) scope. This installer uses a dual-scope MSI package that installs to %LocalAppData%\\Programs for user scope and %ProgramFiles% for machine scope, and it automatically configures the PATH environment variable for the appropriate scope. The installation process includes a welcome dialog where users can select their virtualization provider (WSLv2 or Hyper-V), and it prevents installation if a legacy machine-scope Podman installation is detected to avoid conflicts.
contrib/win-installer/wix · high confidence
New Windows path management utility for installer integration
A new standalone utility (cmd/winpath) has been added to handle Windows PATH environment variable modifications. This tool allows the installer to add or remove the Podman directory from the user's PATH via registry updates and broadcasts environment change notifications to running applications. It also supports an internal 'open' command to launch the Windows tutorial after MSI installation.
cmd/winpath · high confidence
New \`podman kube apply\` command for deploying Kubernetes resources to a cluster
A new \podman kube apply\ command has been added to the local ABI engine, enabling users to deploy Kubernetes manifests (Pods, Services, and PersistentVolumeClaims) directly to a remote Kubernetes cluster. The command reads a kubeconfig file, establishes a secure HTTP connection using client certificates and CA data, and creates the specified resources via the Kubernetes API. It supports multi-document YAML files and allows users to specify the target namespace and kubeconfig path.
pkg/domain/infra/abi · high confidence
New channel package for io.Writer to channel proxying
Added a new \pkg/channel\ package that provides a \WriteCloser\ implementation, allowing users to proxy \io.Writer\ calls to a Go channel. This includes a \NewWriter\ constructor, a \Chan()\ accessor, and thread-safe \Write\ and \Close\ methods that queue byte slices and handle edge cases like nil receivers or writes after close. The addition is accompanied by comprehensive unit tests covering message queuing, buffer copying, order preservation, and error handling.
pkg/channel · high confidence
New checkpoint/restore utility functions in crutils
The new \pkg/checkpoint/crutils/checkpoint\_restore\_utils.go\ file introduces a set of helper functions to manage checkpoint archives and container filesystem states during restore. Specifically, it adds \CRImportCheckpointWithoutConfig\ and \CRImportCheckpointConfigOnly\ to selectively extract checkpoint data, \CRRemoveDeletedFiles\ to clean up files marked as deleted during the checkpoint process, and \CRApplyRootFsDiffTar\ and \CRCreateRootFsDiffTar\ to handle root filesystem diffs (adding, modifying, or deleting files) to ensure the restored container matches its state at checkpoint time. These utilities rely on \chrootarchive\ for tar operations and \securejoin\ for safe path resolution.
pkg/checkpoint/crutils · high confidence
New developer tooling and CI scripts for testing, linting, and documentation
The \hack/\ directory has been populated with a suite of new scripts to improve the development workflow. A new \hack/bats\ wrapper simplifies running system tests with root, rootless, and remote modes. Documentation generation is supported by \hack/markdown-preprocess\ (a Python-based preprocessor for man pages) and \hack/man-page-checker\ (which validates man page consistency against \--help\ output). CI and maintenance are enhanced by \hack/buildah-vendor-treadmill\ for automated vendoring, \hack/golangci-lint.sh\ for multi-platform linting, and \hack/commit-subject-check.sh\ for commit message validation. Additional utilities include \hack/fork\_exec\_snoop.bt\ for eBPF-based process tracing, \hack/branch\_commits.rb\ for release branch analysis, and various build-tag checkers for AppArmor, btrfs, and libsubid.
hack · high confidence
New domain entity types and engine interfaces for Podman v6
This change introduces a comprehensive set of new domain entity types and engine interfaces in \pkg/domain/entities\ to support the Podman v6 API and CLI. It defines the data structures and options for core operations including container management (create, run, inspect, logs, stats, wait, exec, checkpoint/restore), image handling (pull, push, build, manifest, artifact, SCP), pod and volume management, Kubernetes integration (play/generate kube, apply), and system administration (auto-update, secrets, quadlets, machine, network, pruning). The \ContainerEngine\ and \ImageEngine\ interfaces consolidate the method signatures for these operations, while specific option structs (e.g., \ContainerRunOptions\, \ImagePullOptions\, \PlayKubeOptions\) expose the configuration parameters for each command. Additionally, it includes event conversion utilities and tests to ensure compatibility between internal libpod events and the external API entity format.
pkg/domain/entities · high confidence
New error handling utilities and API error models
Added a new \pkg/errorhandling\ package providing helper functions for managing error slices (\JoinErrors\, \ErrorsToStrings\, \StringsToErrors\), a \CloseQuiet\ utility for file operations, and a \Contains\ function for string-based error matching. It also introduces \ErrorModel\ and \PodConflictErrorModel\ structs to standardize API error responses, specifically handling HTTP 409 conflicts for pod actions, and includes a \Cause\ function to unwrap errors up to a safe depth limit.
pkg/errorhandling · high confidence
New generic thread-safe map implementation
A new generic, thread-safe map type has been added to the codebase to provide a cleaner alternative to the standard library's sync.Map for scenarios where code readability is prioritized over raw performance. This Map supports standard operations like Put, Get, Exists, and Delete, and includes methods to safely retrieve a shallow copy or access the underlying storage directly.
pkg/syncmap · high confidence
New internal utility for converting Go structs to URL query parameters
The \pkg/bindings/internal/util\ package now provides internal helpers to serialize Go structs into \url.Values\ for API requests. The \ToParams\ function supports simple types, slices, and maps (serialized as JSON), respects \schema\ struct tags for renaming or skipping fields, and correctly handles nil pointers. This change introduces the implementation and its test suite, marking the utility as internal to the bindings layer.
pkg/bindings/internal · high confidence
New macOS helper agent for Docker socket forwarding
A new privileged helper service (podman-mac-helper) is introduced for macOS to manage the /var/run/docker.sock symlink. The helper installs a launchd agent that redirects docker.sock to the user-specific Podman machine socket, enabling Docker-compatible tooling to connect to Podman. Users can install, uninstall, or manage this helper via the new 'install' and 'uninstall' commands, with the service running as root to handle symlink creation and removal securely.
cmd/podman-mac-helper · high confidence
New machine configuration and definition types
The \pkg/machine/define\ package now introduces structured types and constants for managing Podman machine configurations, including \InitOptions\ and \SetOptions\ that support new capabilities like USB passthrough, swap configuration, and native CA import. It defines \VMType\ to map hypervisors (QEMU, WSL, AppleHV, HyperV, LibKrun) to specific image formats (e.g., Tar for WSL, Raw for AppleHV) and compression (zstd), while \VMFile\ handles file path management with symlink support for macOS. Additionally, it establishes error types for state management and constants for default machine names and paths.
pkg/machine/define · high confidence
New namespace mode types and validation logic
The \pkg/namespaces\ package introduces \UsernsMode\ and \NetworkMode\ types with methods to identify specific namespace configurations, including support for \keep-id\, \auto\, \nomap\, and \pasta\ network modes. This change provides the core validation and parsing logic for these new options, ensuring users can correctly configure user and network namespaces via flags like \--userns=keep-id\ or \--network=pasta\.
pkg/namespaces · high confidence
New parsing API for podman cp source and destination arguments
The \pkg/copy\ package now exposes a \ParseSourceAndDestination\ function that correctly interprets the \\[nameOrID:\]path\ syntax for both source and destination arguments. This change introduces robust handling for container names, absolute and relative paths, and edge cases such as colons within paths (e.g., \./weird:name\ or \/abs/weird:name\) and Windows drive letters, ensuring that the copy command accurately distinguishes between container identifiers and file paths. The implementation includes new helper logic in \fileinfo.go\ for resolving host paths and preserving base path semantics, along with comprehensive tests validating the parsing behavior.
pkg/copy · high confidence
New podman kube subcommand with play, generate, apply, and down commands
Podman now includes a dedicated \podman kube\ command group that provides a complete lifecycle for Kubernetes YAML workflows. The \play\ command creates and manages pods, deployments, daemonsets, jobs, and persistent volume claims from YAML files (including remote URLs), while \generate\ creates Kubernetes YAML specifications from existing containers, pods, or volumes. The new \apply\ command deploys workloads to a Kubernetes cluster using a kubeconfig, and \down\ removes pods based on the provided YAML. This replaces the legacy \podman play kube\ command with a more structured interface.
cmd/podman/kube · high confidence
New podman system check command for storage consistency
A new \podman system check\ command has been added to detect and repair damage in local storage. It scans for damaged layers, images, and containers, reporting any issues found. When used with the \--repair\ or \--force\ flags, it automatically removes inconsistent images or containers to restore storage integrity. The command also supports a \--quick\ mode to skip time-consuming checks and a \--max\ flag to define the maximum age of unreferenced layers to consider.
cmd/podman/system · high confidence
New reverse file reader for log output
A new \ReverseReader\ component has been added to \libpod/logs/reversereader\ to enable reading log files from the end backwards. This implementation uses page-sized reads to efficiently retrieve the most recent log entries, which supports the \podman logs --tail\ functionality by allowing the system to fetch the last N lines without loading the entire file into memory.
libpod/logs/reversereader · high confidence
New rootless namespace management and ID mapping utilities
The \pkg/rootless\ package now provides core infrastructure for managing rootless user namespaces, including functions to retrieve available UID/GID mappings (\GetAvailableUIDMap\, \GetAvailableGIDMap\), handle pause process namespace joining (\TryJoinPauseProcess\), and automatically split ID mappings when necessary (\MaybeSplitMappings\). It also introduces platform-specific support for FreeBSD (with stub implementations for unsupported features) and adds a C-level helper to detect inherited file descriptors, improving reliability during rootless re-execution.
pkg/rootless · high confidence
New signal handling package for consistent signal parsing and proxying
The new \pkg/signal\ package introduces a unified way to parse signal names and numbers (e.g., "KILL", "9") and manage signal catching across different operating systems. It provides \CatchAll\ and \StopCatch\ functions to relay signals to a specified channel while ignoring specific system signals like SIGCHLD, SIGPIPE, SIGURG, and SIGSTOP that are intended for the command itself. The package includes platform-specific implementations for Linux (including MIPS variants), other Unix-like systems, and unsupported platforms, ensuring consistent signal behavior and enabling features like Podman remote signal proxying.
pkg/signal · high confidence
New socket utility functions for connection and path handling
The pkg/machine/sockets package introduces new utilities to manage Unix socket interactions for machine operations. It adds functions to wait for and accept socket connections (ListenAndWaitOnSocket), attempt connections with exponential backoff (DialSocketWithBackoffs), and perform connection attempts with process health checks (DialSocketWithBackoffsAndProcCheck). Additionally, it provides a method to wait for a socket file to exist (WaitForSocketWithBackoffs) and a utility to convert VM file paths into Unix socket URLs (ToUnixURL), replacing previous inline implementations or external dependencies like fileutils.Exists for existence checks.
pkg/machine/sockets · high confidence
New specgenutil package for container specification generation
A new \pkg/specgenutil\ package has been introduced to centralize the parsing and validation of container creation options. This change adds logic to handle port exposure ranges (e.g., \--expose 100-133\), normalize PID limits for OCI compatibility (mapping 0 to unlimited), and unify volume/mount parsing from \--mount\, \--volume\, and \--tmpfs\ flags. It also includes validation for \--rm\ and \--restart\ flag conflicts, Windows path conversion for mounts, and seccomp profile path handling on Windows.
pkg/specgenutil · high confidence
New system bindings for Podman v6 API operations
The \pkg/bindings/system\ package now provides Go bindings for several Podman system-level API endpoints in the v6 module. Users can now programmatically retrieve environment information (\/info\), monitor container events with streaming support (\/events\), check and repair storage consistency (\/system/check\), view disk usage for images, containers, and volumes (\/system/df\), and retrieve detailed version information including OS and build time (\/version\). Additionally, the package supports pruning unused system data (\/system/prune\) with options to include external volumes and build caches. These bindings replace previous implementations and align with the updated Podman v6 API structure.
pkg/bindings/system · high confidence
New utility functions for parsing, filtering, and mount option validation
The \pkg/util\ package introduces several new capabilities to support container operations. \DecodeChanges\ normalizes Dockerfile-style change strings (e.g., converting \CMD=/bin/sh\ to \CMD /bin/sh\) to ensure compatibility with strict parsers. \FiltersFromRequest\ and \PrepareFilters\ handle backward-compatible parsing of HTTP filter parameters, supporting both legacy \map\[string\]map\[string\]bool\ and modern \map\[string\]\[\]string\ formats. \NormalizeVolumePruneFilters\ aligns volume pruning behavior with Docker by correctly handling the \all\ flag alongside label filters. \ProcessOptions\ validates and sanitizes bind and tmpfs mount options, enforcing rules such as mutual exclusivity for \rw\/\ro\ and restricting tmpfs-specific options like \size\ and \mode\. Additionally, \FindDeviceNodes\ scans \/dev\ to map device nodes by major/minor numbers, and \FormatRlimits\ clamps resource limits to host maximums for rootless containers.
pkg/util · high confidence
New utility functions for port allocation, command execution, and file operations
The utils package now includes new helper functions to improve reliability and usability. GetRandomPort() allows finding a free TCP port on the host, which is useful for services that need dynamic port assignment. ExecCmd() and ExecCmdWithStdStreams() provide standardized ways to run external commands with proper error handling and stream management. TarToFilesystem() and TarWithChroot() simplify creating tarballs from source directories, with chroot support for secure content export. GuardedRemoveAll() and RemoveFilesExcept() add safety checks to prevent accidental deletion of critical paths like root. ProgressBar() offers a consistent progress bar interface for long-running operations.
utils · high confidence
New v2 libpod API handlers for containers, images, and system operations
This change introduces a comprehensive set of new API handlers in the \pkg/api/handlers/libpod\ package, implementing the v2 REST API endpoints for core Podman operations. The new handlers cover container lifecycle management (create, list, inspect, wait, mount/unmount), image operations (pull, push, prune, tree, export), and system-level functions (generate systemd units, generate Kubernetes manifests, run health checks, and auto-update). The implementation leverages the ABI engine layer to execute these operations, ensuring consistency with local commands while exposing them via the HTTP API. Specific features include support for streaming stats, configurable pull/push retry logic, TLS verification options, and the ability to play Kubernetes YAML files (including tar archives) through the API.
pkg/api/handlers/libpod · high confidence
New zsh completion scripts for podman and podman-remote
Added new zsh completion scripts (\\_podman\ and \\_podman-remote\) that enable dynamic command-line completion. These scripts integrate with the shell to provide context-aware suggestions for commands, flags, and arguments, including support for active help messages, file/directory filtering, and proper handling of flag syntax (e.g., \--flag=value\).
completions/zsh · high confidence
Parallel container operations on Linux and FreeBSD
The \pkg/parallel/ctr\ package now provides a \ContainerOp\ function that executes operations on multiple containers concurrently using a thread pool. This capability is restricted to Linux and FreeBSD platforms (excluding remote mode) and relies on the \go.podman.io/podman/v6\ module paths. Users can now perform batch container actions with improved performance through parallel execution.
pkg/parallel/ctr · high confidence
Pod management bindings now support prune, stats, and top operations
The Go bindings for pod management in \pkg/bindings/pods\ have been expanded to include new operations for pod lifecycle and monitoring. Users can now prune non-running or all pods via the \Prune\ function, retrieve resource usage statistics with \Stats\, and view running processes within a pod using \Top\. These additions are supported by corresponding option structs (\PruneOptions\, \StatsOptions\, \TopOptions\) and their generated parameter-handling code, allowing for more granular control and visibility into pod states through the API.
pkg/bindings/pods · high confidence
Podman CLI v6: New command structure and remote compose support
The Podman CLI has been restructured for version 6, introducing a new command registration system via the \registry.Commands\ slice and a \main.go\ entry point that wires in subcommands (such as \manifest\, \farm\, \quadlet\, and \machine\) through Go package imports. This release adds a new \podman auto-update\ command for managing containers according to auto-update policies, and significantly enhances \podman compose\ to support remote connections and Podman machines by dynamically configuring the \DOCKER\_HOST\ environment variable for external providers. Additionally, the \podman login\ command now supports retrieving passwords from Podman secrets via the \--secret\ flag, and the CLI now includes platform-specific early initialization hooks to set \RLIMIT\_NOFILE\ and \umask\ on Linux and macOS.
cmd/podman · high confidence
Podman Go bindings for volumes now support rename, existence checks, and import/export
The \pkg/bindings/volumes\ package has been updated to expose new volume management capabilities via the Podman API. Users can now rename volumes using the new \Rename\ function, verify a volume's presence with \Exists\, and transfer volume data using \Export\ and \Import\. The bindings also support filtering during volume listing and pruning, and allow forced removal with a timeout. These changes are implemented in the Go bindings located in \pkg/bindings/volumes\.
pkg/bindings/volumes · high confidence
Podman REST API v6.0.0 server implementation
The Podman REST API server has been updated to version 6.0.0, introducing a comprehensive set of new and refactored HTTP endpoints. This release adds support for OCI artifacts (listing, inspecting, pulling, and removing), auto-update policies for containers, and a distribution inspect endpoint to retrieve image metadata from registries. The API now includes handlers for generating systemd units, running container healthchecks, and managing container archives (copying files in and out). Additionally, the server implements a buffered response writer to improve streaming reliability for clients with broken JSON parsing, adds CORS support, and introduces an X-Reference-Id header for request correlation and logging.
pkg/api/server · high confidence
Podman machine now claims /var/run/docker.sock on macOS
On macOS, Podman machine now attempts to claim the global Docker socket (/var/run/docker.sock) to allow Docker CLI commands to interact with the Podman VM. This is achieved by introducing a new shim layer that checks for the presence of the \podman-mac-helper\ service, coordinates socket ownership via a user-global socket link, and falls back to a machine-local socket if the global claim fails or is unsupported. On other platforms, this behavior is disabled, and Windows uses named pipes for API forwarding instead.
pkg/machine/shim · high confidence
Podman machine now pulls OS images from OCI registries
Podman machine can now download virtual machine disk images directly from OCI registries instead of relying on legacy sources. The new \pkg/machine/ocipull\ package handles fetching disk artifacts (such as qcow2, raw, or vhdx files) by resolving the correct architecture and compression type from the registry manifest, caching the pulled images locally to avoid redundant downloads, and decompressing them for use. It also supports optional TLS verification and falls back to a permissive signature policy if no host-level policy is configured, allowing users to initialize machines using standard container image distribution mechanisms.
pkg/machine/ocipull · high confidence
Podman network CLI commands restructured and expanded
The network management commands have been reorganized into a dedicated subcommand structure (podman network). This update introduces new capabilities including the ability to connect and disconnect containers to networks with static IP, IPv6, and MAC address assignments, and to create networks with multiple subnets, static routes (including blackhole, unreachable, and prohibit types), and custom DNS servers. The network list command now supports filtering and deterministic sorting, while the remove command adds an --ignore flag for idempotent scripting and a --time flag to specify container stop timeouts. Additionally, a new network exists command allows checking for network presence, and the reload command enables reloading firewall rules for containers.
cmd/podman/networks · high confidence
Podman v6 remote client infrastructure restructured
The remote client implementation in \pkg/domain/infra/tunnel\ has been completely rewritten for Podman v6, replacing the previous v2 bindings with new v6-specific API bindings. This change introduces dedicated engine types (\ImageEngine\, \ContainerEngine\, \SystemEngine\) and implements tunnelled support for a broad set of commands including artifacts, auto-update, containers, events, farm builds, health checks, images, Kubernetes operations, manifests, networks, pods, quadlets, secrets, and volumes. The new structure standardizes how remote operations are executed via the Podman service, ensuring parity with local commands while handling remote-specific constraints such as unsupported local-only features (e.g., image mounting, quadlet installation).
pkg/domain/infra/tunnel · high confidence
Support for OCI registry and HTTP URL disk image sources
The disk pull mechanism now supports retrieving machine images from OCI registries (including docker:// prefixed paths) and direct HTTP URLs, in addition to local file paths. This allows users to initialize Podman machines using remote image sources, with optional TLS verification control for OCI pulls.
pkg/machine/shim/diskpull · high confidence
Support for X-Registry-Config header in authentication
The authentication package now supports the X-Registry-Config HTTP header, allowing clients to pass authentication configurations for multiple registries in a single Base64-encoded JSON map. This complements the existing X-Registry-Auth header, which continues to support single-registry authentication. The GetCredentials function now checks for X-Registry-Config first, enabling more efficient handling of multi-registry scenarios in API requests.
pkg/auth · high confidence
Support for advanced volume creation options (UID, GID, size, inodes, timeout, noquota)
The volume creation parser now handles additional options passed via the 'o' flag, allowing users to specify size, inodes, UID, GID, timeout, and noquota when creating builtin volumes. These options are parsed and converted into specific libpod volume creation options (e.g., WithVolumeSize, WithVolumeUID, WithVolumeDriverTimeout), enabling more granular control over volume properties directly from the CLI.
pkg/domain/infra/abi/parse · high confidence
Support for restoring containers into pods and importing checkpoint tarballs
The checkpoint/restore functionality now supports restoring containers into existing pods, validating that the target pod shares the necessary namespaces (IPC, network, PID, UTS, cgroup) and updating the container's configuration to align with the pod's infrastructure container. Additionally, a new import path allows users to restore containers from checkpoint tarballs, handling the extraction of container specs and configurations, and enforcing checks for named volumes and pod consistency during the import process.
pkg/checkpoint · high confidence
Architecture
Domain entity types reorganized into a dedicated sub-package
The domain entity structs (such as ContainerUpdateOptions, ImageSummary, and PlayKubeReport) have been moved from the \entities\ package into a new \entities/types\ sub-package. This structural change consolidates all type definitions in one location, simplifying imports for other parts of the codebase like the API bindings and CLI commands that previously had to reference the broader \entities\ package.
pkg/domain/entities/types · high confidence
Refactor container listing logic into a dedicated ps package
The container listing functionality has been moved from the main libpod package into a new, dedicated \pkg/ps\ package. This change introduces a new \ContainerSize\ type to expose root filesystem and read-write layer sizes in the output, and restructures the core \GetContainerLists\ and \ListContainerBatch\ functions to handle container filtering, external container integration, and batched state retrieval more cleanly. Users will see no functional change in the \podman ps\ command itself, but the underlying implementation is now modularized for better maintainability and performance.
pkg/ps · high confidence
Behavioural changes
Add CRIU version checking and support for pod checkpoint/restore
The pkg/criu package now enforces minimum CRIU version requirements, distinguishing between the general minimum (3.11) and the higher version (3.16) needed for pod checkpoint/restore. It integrates the go-criu v8 library to detect the installed CRIU version and verify feature support (such as memory tracking) on Linux, while providing stub implementations for unsupported platforms.
pkg/criu · high confidence
Add TMT reverse-dependency test plans for podman, tmt, and toolbox
New TMT (Test Management Tool) plans have been added to the repository to enable reverse-dependency testing for cockpit-podman, tmt, and toolbox. The cockpit-podman plan mirrors the project's test structure (system, user, and misc) and is triggered by the 'revdeps' flag. The system plan provides a baseline environment with specific hardware requirements (16GB RAM, 4+ cores) and archives audit and journal logs for post-test analysis. The tmt plan runs tests tagged with 'podman' from the upstream tmt repository, while the toolbox plan executes downstream tests on Fedora. These plans are disabled by default and activated via specific conditions (e.g., 'revdeps == yes' or 'initiator != packit'), allowing CI systems like Packit to run integration tests against updated dependencies.
plans · high confidence
Add race-free locking for concurrent machine start operations
A new lock mechanism has been introduced in the machine package to prevent race conditions when starting multiple virtual machines simultaneously. The \GetMachineStartLock\ function acquires a global lock file (\machine-start.lock\) to ensure that only one machine start operation proceeds at a time, addressing a limitation where most providers support at most one running VM. Additionally, a new \GetMachineLock\ function allows for per-machine locking using a lock file located in the machine's configuration directory, facilitating exclusive access checks.
pkg/machine/lock · high confidence
Annotation validation and constant definitions
The pkg/annotations package now provides validation logic for container annotations, enforcing Kubernetes-style qualified name formats (DNS 1123 subdomain prefixes and alphanumeric names) and enforcing a total size limit defined in the define package. It also exposes constants for CRI-O sandbox IDs, container manager indicators, and container types.
pkg/annotations · high confidence
Configure systemd-tmpfiles to manage Podman temporary directories
A new systemd-tmpfiles configuration file (contrib/tmpfile/podman.conf) is introduced to control the lifecycle of Podman's temporary directories. It ensures that runtime directories like /tmp/podman-run-\, /tmp/storage-run-\, /tmp/containers-user-\, and /tmp/run-\/libpod are preserved during periodic cleanups but are recursively removed on reboot. Additionally, it sets permissions for /var/lib/containers/storage/tmp and ensures /var/tmp/container\images\ directories are cleaned up on each boot.
contrib/tmpfile · high confidence
Consolidated and expanded filter logic for containers, pods, and volumes
The filter implementation in \pkg/domain/filters\ has been restructured into dedicated files for containers, pods, and volumes, introducing several new filtering capabilities and standardizing behavior. For containers, users can now filter by annotations (including negated \annotation!\), health status, and volume mounts, while the \ancestor\ filter now supports Docker-compatible substring matching and regex. Pod filtering gains support for \ctr-ids\, \ctr-names\, \ctr-number\, \ctr-status\, \network\, and \until\. Volume filtering is expanded with \dangling\, \anonymous\, \opt\, and \until\ filters, and volume pruning now supports the same filter set as listing. The \status\ filter for both containers and pods now treats 'stopped' as 'exited' to match Docker behavior, and the \name\ filter for containers allows an optional leading slash.
pkg/domain/filters · high confidence
Consolidated environment variable handling in pkg/env
Environment variable processing logic has been consolidated into the new pkg/env package, introducing dedicated functions for parsing, joining, and converting environment maps and slices. This change standardizes how environment variables are managed across the application, including platform-specific handling for Windows (filtering legacy CMD state variables) and Unix systems, and provides utilities like ParseFile for reading .env files and Join for merging environment maps with override support.
pkg/env · high confidence
Deprecate repetitive SELinux labeling functions in favor of SetProcessKind
The pkg/selinux package now exposes KVMLabel and InitLabel functions that are marked as deprecated. These functions serve as thin wrappers around the underlying go-selinux library's SetProcessKind method, effectively consolidating the API by encouraging callers to use the more generic SetProcessKind approach directly rather than relying on specific, repetitive function names for KVM and systemd-based containers.
pkg/selinux · high confidence
Generator now formats output using golangci-lint
The bindings generator in pkg/bindings/generator has been updated to automatically format the generated Go files using golangci-lint. The tool first attempts to locate the binary in a local bin directory and falls back to searching the system PATH, ensuring consistent code style in the generated output without requiring manual formatting steps.
pkg/bindings/generator · high confidence
Hello World image source moved to external repository
The source code and build instructions for the 'hello' container image have been relocated to a dedicated external repository (github.com/containers/PodmanHello). The local contrib/hello directory now contains only a README directing users to the new location and the C source code for the application, while the Containerfile has been removed. This change reflects the migration of the image assets, though the local directory is retained to support legacy tests.
contrib/hello · high confidence
Hyper-V machines can now be managed without Administrator privileges
The Hyper-V machine implementation on Windows has been updated to allow non-administrator users to create, start, and manage machines. This is achieved by automatically adding the user to the local 'Hyper-V Administrators' group during the first initialization (which requires elevation) and by reusing existing hvsock registry entries for subsequent operations. The system now checks for these specific permissions before executing commands, preventing errors for users who are not running as Administrator but have been granted the necessary group rights.
pkg/machine/hyperv · high confidence
Improved WSL installation detection and UTF-8 output handling
The WSL utility layer now enforces UTF-8 encoded output from wsl.exe by setting the WSL\_UTF8 environment variable, which resolves locale-related issues in version detection. Additionally, the logic for checking if WSL is installed has been refined: if the wsl --status command returns an error, the system now assumes WSL is not installed rather than relying solely on output parsing, and error handling for command execution and output scanning has been strengthened to prevent silent failures.
pkg/machine/wsl/wutil · high confidence
Improved log tailing with support for partial lines and colored output
The log handling in libpod/logs has been updated to correctly manage partial log lines when using the --tail option, ensuring that incomplete lines are preserved and displayed rather than dropped. This change also introduces the ability to display container logs with distinct colors per container via the new Colors option, and switches the underlying file tailing library from hpcloud/tail to nxadm/tail for better stability.
libpod/logs · high confidence
Improved signal handling and terminal resizing for exec and attach
The terminal package now ensures that signals (such as SIGINT/SIGTERM) are reliably forwarded to running exec sessions and containers, preventing them from being lost if the session ends unexpectedly. It also adds robust terminal resize support, automatically detecting terminal size changes and updating the container or exec session dimensions in real-time. These changes apply to both \podman exec\ and \podman attach\/\start\ operations on Linux and FreeBSD.
pkg/domain/infra/abi/terminal · high confidence
Improved systemd socket activation and rootless D-Bus connectivity
The systemd package now provides more robust support for socket activation and rootless environments. Socket activation detection no longer requires the LISTEN\_FDNAMES environment variable, allowing activation to succeed with just LISTEN\_PID and LISTEN\_FDS. Additionally, new D-Bus integration enables rootless users to connect to systemd-logind via the XDG\_RUNTIME\_DIR, evaluating symlinks in that path to establish a valid session connection.
pkg/systemd · high confidence
Initialize FMTF metadata version
The project now includes a \.fmf/version\ file declaring version 1, establishing the baseline for FMTF (Framework for Metadata) metadata usage. This change supports the CI configuration updates that enable running cockpit-podman tests in pull requests by ensuring the metadata tree is properly versioned and recognized by the test infrastructure.
.fmf · low confidence
Introduces flag aliases and refined exit-code handling for CLI compatibility
The \cmd/podman/utils\ package now provides utilities to improve command-line compatibility and error reporting. It adds an alias system (\AliasFlags\) that maps legacy or shorthand flags (such as \dns-opt\, \net\, \storage\, and \notruncate\) to their canonical names, ensuring smoother transitions and alignment with Docker conventions. Additionally, it introduces \TimeoutAliasFlags\ to map \timeout\ to \time\. The package also implements robust exit-code handling via \HandleOSExecError\ and \ExitCodeFromBuildError\, which correctly parse and propagate exit statuses from underlying OS executions and build errors, ensuring that commands like \podman unshare\ or remote builds return accurate exit codes to the user.
cmd/podman/utils · high confidence
Local API path validation and machine mount resolution
The local API now enforces that build context and containerfile paths are absolute, returning a new \ErrPathNotAbsolute\ error if they are not. It also introduces logic to verify that these local paths are accessible within the running Podman machine's mounted directories; if a path is found within a mount, the API translates the local client path to the corresponding remote path inside the VM. This ensures that direct filesystem builds on macOS and Windows (via WSL) correctly resolve host paths to their locations inside the guest machine.
internal/localapi · high confidence
Migrate CI infrastructure from Cirrus to GitHub Actions with Lima VM testing
The CI system has moved from Cirrus CI to GitHub Actions, introducing a new Lima-based virtual machine environment for running integration and system tests. This change includes new scripts to manage the VM lifecycle (ci.sh), a Python-based validator for the GitHub Actions workflow configuration (ci\_yaml\_test.py), and improved log processing tools (logformatter, github\_log\_summary) to provide better visibility into test failures. The migration also brings in specific cleanup scripts for macOS runners and automation for fetching local registry images, ensuring consistent and faster test execution within the new GitHub-hosted environment.
hack/ci · high confidence
Migrate \`podman play kube\` to the new specgen generation layer
The \pkg/specgen/generate/kube\ package has been rewritten to serve as the dedicated specification generator for \podman play kube\ and \podman kube generate\. This change consolidates the logic for parsing Kubernetes YAML manifests into Podman container specifications, introducing support for a broader range of Kubernetes features including init containers, CDI resource allocation, host device passthrough (block and character devices), and persistent volume claims. The new implementation also enforces stricter validation, such as detecting duplicate host port bindings across containers, and correctly handles complex volume sources like ConfigMaps, Secrets, and EmptyDirs (including tmpfs-backed memory volumes).
pkg/specgen/generate/kube · high confidence
New RPM build infrastructure and packaging structure
The RPM build process has been restructured with the introduction of a dedicated Makefile and version update script, streamlining local and CI builds. The packaging now includes a new \podmansh\ subpackage for confined user shells, adds \containers-common-extra\ as a required dependency for the new configuration layout, and restricts the \podman-machine\ subpackage to specific architectures (x86\_64, aarch64). Additionally, Fedora 43+ builds now require \podman-sequoia\, and the build system enforces SPDX-compatible license fields and uses vendored \go-md2man\.
rpm · high confidence
New argument validation helpers and --latest flag scoping
The \cmd/podman/validate\ package now provides reusable validation functions (\NoArgs\, \SubCommandExists\, \IDOrLatestArgs\, \CheckAllLatestAndIDFile\) and a \ChoiceValue\ type for flag validation. A key behavioral change is that the \--latest\ (and \-l\) flag is no longer available for remote commands, as it is explicitly skipped when \registry.IsRemote()\ is true. Additionally, the \--latest\ flag cannot be used together with container names/IDs, and \--filter\ now correctly rejects arguments.
cmd/podman/validate · high confidence
New image inspection data structure with Docker-compatible fields
The \pkg/inspect\ package now defines an \ImageData\ struct that exposes detailed image metadata, including history layers, health check configurations, and user information. This structure aligns the inspect output with Docker's format by including fields such as \NamesHistory\, \Healthcheck\, and \User\, ensuring better compatibility for users relying on standard inspect data.
pkg/inspect · high confidence
New machine configuration schema and provider-specific settings
The \pkg/machine/vmconfigs\ package has been rewritten to introduce a new machine configuration structure (\MachineConfig\) that supports provider-specific settings for Apple Hypervisor, Hyper-V, LibKrun, QEMU, and WSL. This change adds support for configuring swap space, USB passthrough, and rootful mode, while also introducing atomic configuration file writes and platform-specific socket and volume path handling.
pkg/machine/vmconfigs · high confidence
New report types for container removal, pruning, and SCP operations
The \pkg/domain/entities/reports\ package now includes structured report types for \rm\, \prune\, and \scp\ commands. The \RmReport\ type exposes container IDs and errors, while the \PruneReport\ type adds a \Size\ field to report reclaimed space and implements custom JSON marshaling to safely serialize error messages. Additionally, a basic \ScpReport\ type is introduced for image SCP operations, and tests verify the correct JSON handling of the prune report, including complex error strings.
pkg/domain/entities/reports · high confidence
New systemd unit file parser with robust escaping and unescaping
The \pkg/systemd/parser\ package now provides a dedicated parser for systemd unit files, replacing previous ad-hoc handling. This new implementation correctly processes C-style escape sequences (including octal, hex, and Unicode) in values, handles line continuations, and supports both \\#\ and \;\ for comments. It also introduces proper escaping for paths and words, ensuring that special characters like spaces, slashes, and dashes are handled according to systemd conventions, which fixes issues with volumes containing spaces or long paths.
pkg/systemd/parser · high confidence
Platform-specific provider detection and permission checks for Podman machines
The provider detection logic is now split into platform-specific files (Darwin, Windows, Unix) to correctly identify and initialize the appropriate virtualization backend for each OS. On macOS, the system now supports both AppleHV and LibKrun providers, with LibKrun detection verifying the presence of required binaries like krunkit. On Windows, the provider selection defaults to WSL but also supports Hyper-V, including a new permission check that ensures users have the necessary rights to execute machine commands. On Linux and other Unix systems, QEMU remains the default provider. Additionally, a new utility function GetAllMachinesAndRootfulness has been added to aggregate rootfulness status across all configured machines from all available providers.
pkg/machine/provider · high confidence
Podman Go bindings for images are rewritten for v6
The \pkg/bindings/images\ package has been completely rewritten to align with the Podman v6 API. This change introduces new Go bindings for image operations including build, pull, push, list, inspect, tree, history, load, export, prune, and remove. The implementation now uses the v2 API endpoints, supports remote builds with additional context paths and Windows path conversion, and includes progress reporting for pull and push operations. The bindings also support new features like compression format options, TLS verification skipping, and manifest list operations.
pkg/bindings/images · high confidence
Podman Go bindings v6: SSH stdio fallback and connection improvements
The Go bindings have been updated to version 6, introducing a dial-stdio fallback mechanism for SSH connections to handle environments where direct-streamlocal channels are refused, alongside support for TCP connections via proxies and improved error handling for non-JSON responses. The connection logic now automatically corrects malformed unix:// URIs, respects HTTP path prefixes for TCP connections to match Docker context behavior, and provides more helpful error messages for machine users. Additionally, the bindings now include a new APIVersionError type to clearly indicate when an endpoint requires a newer server version, and the module path has been updated to go.podman.io/podman/v6.
pkg/bindings · high confidence
Podman V2 engine mode and remote connection handling
Podman now uses a V2 architecture that distinguishes between local (ABI) and remote (Tunnel) engine modes, defaulting to Tunnel mode on macOS and Windows, and on Linux/FreeBSD when the remote flag or connection options are used. The --remote flag is now enabled and implied by --connection, --context, --host, and --url, allowing users to connect to remote Podman engines more easily. The --module flag supports StringArray inputs for specifying modules, and the log level is applied before loading the configuration to ensure early logging works correctly. Shell completion and podmansh are handled to avoid conflicts with remote mode parsing.
cmd/podman/registry · high confidence
Podman diff command now supports comparing two containers or images
The \podman diff\ command has been updated to accept two arguments, allowing users to compare the differences between two containers or images rather than just inspecting a single one. The implementation in \cmd/podman/diff/diff.go\ validates that either one argument is provided or two are provided (unless the \--latest\ flag is used), and passes these arguments to the underlying engine. The output formatting logic remains unchanged, supporting both table and JSON formats for displaying added, deleted, and modified paths.
cmd/podman/diff · high confidence
Podman manifest commands rewritten for v6 with expanded artifact and TLS options
The \podman manifest\ subcommands (add, annotate, create, exists, inspect, push, remove, rm) have been rewritten for Podman v6, introducing support for OCI artifacts via the \--artifact\ flag and related options (e.g., \--artifact-type\, \--artifact-config\), stricter TLS verification handling with \--tls-verify\ and \--insecure\ flags, and new capabilities such as \--digestfile\ for push output, \--retry\/\--retry-delay\ for push resilience, and \--ignore\ for the \rm\ command. The \annotate\ command now supports \--index\ to modify the entire index, and \create\ accepts \--amend\ to modify existing lists.
cmd/podman/manifest · high confidence
Podman systemd generator refactored with improved argument handling and dependency management
The \podman generate systemd\ command has been significantly refactored to improve the robustness and correctness of generated unit files. Argument parsing is now stricter: container and pod-specific flags (like \--pod\, \--cidfile\, \--sdnotify\) are correctly filtered from the \ExecStart\ command to prevent conflicts, and arguments containing whitespace or special systemd characters (\$\, \%\, \ \) are properly quoted or escaped. The generator now supports user-defined systemd dependencies (\Wants\, \After\, \Requires\) for both containers and pods, allowing finer control over service startup order. Additionally, generated units now include \RequiresMountsFor\ directives to ensure storage mounts are ready, use \default.target\ for installation, and set \Type=notify\ for containers where appropriate, while pods remain \Type=forking\. The tool also now validates restart policies and warns if existing containers have restart policies that might conflict with systemd's management.
pkg/systemd/generate · high confidence
Podman v6 image management commands restructured under 'podman image'
The image management commands (build, diff, exists, history, import, inspect, list, load, mount, prune, pull, push, rm, save) have been reorganized under a new 'podman image' subcommand hierarchy, while retaining the original top-level aliases (e.g., 'podman build', 'podman images') for backward compatibility. This change introduces a new 'podman buildx' command (hidden by default) to improve Docker compatibility, including a 'buildx inspect' subcommand that displays local builder capabilities. The 'podman image list' output now includes 'Repository' and 'Tag' fields in JSON format and supports sorting by repository. The 'podman image history' command now formats the 'Created' timestamp in RFC3339 format for JSON output and human-readable relative time for table output. The 'podman image load' command now supports loading images from HTTP/HTTPS URLs via the '--input' flag. The 'podman image pull' command now supports pulling multiple images in a single call and includes new flags for retry logic ('--retry', '--retry-delay') and decryption keys ('--decryption-key'). The 'podman image push' command now supports pushing manifest lists by default and includes new flags for compression ('--force-compression', '--compression-format', '--compression-level') and digest file output ('--digestfile'). The 'podman image rm' command now supports the '--ignore' flag to ignore errors if an image does not exist. The 'podman image mount' command now supports mounting multiple images and printing results in JSON format. The 'podman image prune' command now supports removing build cache ('--build-cache') and external containers ('--external'). The 'podman image import' command now supports setting the OS, architecture, and variant of the imported image. The 'podman image diff' command now supports comparing two images. The 'podman image exists' command has been added to check if an image exists in local storage. The 'podman image inspect' command has been added to display low-level information of an image. The 'podman image history' command has been added to show the history of an image. The 'podman image load' command has been added to load an image from a tar archive. The 'podman image mount' command has been added to mount an image's root filesystem. The 'podman image prune' command has been added to remove unused images. The 'podman image pull' command has been added to pull an image from a registry. The 'podman image push' command has been added to push an image to a specified destination. The 'podman image rm' command has been added to remove one or more images from local storage. The 'podman image save' command has been added to save an image to an archive. The 'podman image build' command has been added to build an image using instructions from Containerfiles. The 'podman image diff' command has been added to inspect changes to the image's file systems. The 'podman image exists' command has been added to check if an image exists in local storage. The 'podman image history' command has been added to show the history of an image. The 'podman image import' command has been added to import a tarball to create a filesystem image. The 'podman image inspect' command has been added to display the configuration of an image. The 'podman image list' command has been added to list images in local storage. The 'podman image load' command has been added to load image(s) from a tar archive. The 'podman image mount' command has been added to mount an image's root filesystem. The 'podman image prune' command has been added to remove unused images. The 'podman image pull' command has been added to pull an image from a registry. The 'podman image push' command has been added to push an image to a specified destination. The 'podman image rm' command has been added to remove one or more images from local storage. The 'podman image save' command has been added to save image(s) to an archive.
cmd/podman/images · high confidence
QEMU machine implementation refactored for Podman 6
The QEMU machine provider has been restructured to support the new Podman 6 machine architecture. This includes a new configuration lookup mechanism using \config.FindHelperBinary\ for locating the QEMU binary, platform-specific command-line option generation for Linux, FreeBSD, and Windows (including WSL and Hyper-V acceleration), and a dedicated \QEMUStubber\ that manages the VM lifecycle via the QMP monitor. The update also introduces \virtiofsd\ integration for host directory mounts, USB host passthrough support, and cross-platform process management for stopping and verifying VM status.
pkg/machine/qemu · high confidence
Redesign of podman system connection management commands
The \podman system connection\ subcommands have been restructured to provide a more consistent and feature-rich experience for managing remote service destinations. The \add\ command now supports explicit scheme-based destinations (ssh, tcp, unix) and includes TLS configuration flags (--tls-ca, --tls-cert, --tls-key) for secure TCP connections, along with options to set a default connection or assign it to a farm. The \list\ command has been enhanced with a \--format\ flag to allow output as JSON, custom Go templates, or a specific 'tls' view that exposes certificate details, and results are now deterministically sorted by name. A new \default\ command (aliased as \use\ under \context\) simplifies setting the active connection. Additionally, \remove\ now supports an \--all\ flag to clear all connections and associated farm memberships, and a new \rename\ command allows changing a connection's name while preserving its configuration and default status.
cmd/podman/system/connection · high confidence
Refactor API parameter decoding and type definitions
The API handlers now use a centralized decoder (decoder.go) to handle query parameter conversion for complex types like time, container status, and signals, replacing previous ad-hoc parsing. Additionally, type definitions (types.go) have been updated to embed Moby/Docker API structs directly, ensuring closer compatibility with the Docker Engine API, while deprecating legacy fields such as Container and ContainerConfig in image inspection responses.
pkg/api/handlers · high confidence
Refactor QEMU command construction with Unix domain sockets and memfd memory backends
The QEMU command builder in the Linux machine provider has been restructured to use Unix domain sockets for network devices (via the new \socketVlanNetdev\ helper) and to enable shared memory backends using \memory-backend-memfd\ on Linux systems. This change introduces platform-specific memory handling: Linux builds now configure \memory-backend-memfd\ to support virtiofs, while Windows builds retain the standard \-m\ flag without shared memory objects. The QMP monitor also defaults to Unix sockets, and the module path has been updated to \go.podman.io/podman/v6\.
pkg/machine/qemu/command · high confidence
Refactor driver data retrieval to exclude MergedDir when unmounted
The libpod/driver package now implements logic to remove the 'MergedDir' key from the returned driver metadata if the specified layer is not currently mounted. This ensures that inspection results accurately reflect the container's state by omitting merged directory information for unmounted layers, aligning the output with the actual runtime status of the storage driver.
libpod/driver · high confidence
Refactor libpod/define into modular files and standardize inspect output formats
The \libpod/define\ package has been reorganized into multiple specialized files (annotations, config, container, container\_inspect, containerstate, errors, healthchecks, info, etc.) to reduce duplication and improve maintainability. For users, this brings improved Docker compatibility in \podman inspect\: the \Entrypoint\ field is now consistently returned as an array of strings, and the \StopSignal\ is normalized to Docker's string format. Additionally, \podman inspect\ now exposes new fields such as \StartupHealthCheck\, \HealthcheckOnFailureAction\, \HealthLogDestination\, \SystemdMode\, \Umask\, \Timeout\, \Passwd\, and \SdNotifyMode\ in the container configuration, providing more detailed visibility into container settings and health check behaviors.
libpod/define · high confidence
Refactored VM image decompression with sparse file support and zstd default
The machine compression module has been rewritten to support sparse file creation, which significantly reduces disk usage for VM images by creating holes for large sequences of zero bytes (particularly on macOS). The default compression algorithm for new images is now zstd, and the decompression logic has been refactored to use a generic decompressor interface that handles gzip, bzip2, xz, zip, and uncompressed files, with specific optimizations for zip files that lack magic numbers. Tests have been added to verify decompression correctness and sparse writer behavior.
pkg/machine/compression · high confidence
Refactored machine connection management and SSH URL generation
The connection handling logic in pkg/machine/connection has been restructured to improve how SSH connections are added, updated, and removed. New functions like AddSSHConnectionsToPodmanSocket and UpdateConnectionPairPort now manage connection configurations more explicitly, ensuring that default connections are correctly set or updated based on rootful/rootless states. The internal makeSSHURL helper has been standardized to consistently generate SSH URIs with proper host, port, and user information, and tests have been added to verify this URL construction logic.
pkg/machine/connection · high confidence
Refactored machine environment directory resolution into platform-specific modules
The logic for determining machine-related file paths (config, data, runtime, and SSH identity) has been extracted into the new \pkg/machine/env\ package, with platform-specific implementations for Linux, macOS, FreeBSD, and Windows handling runtime directory resolution. This change introduces a \WithPodmanPrefix\ helper to ensure machine names are consistently prefixed with 'podman-' and adds unit tests for this behavior, while also updating the codebase to use \fileutils.Exists\ for directory existence checks.
pkg/machine/env · high confidence
Refactored spec generation into platform-specific modules with improved device and namespace handling
The container specification generation logic in \pkg/specgen/generate\ has been reorganized into distinct platform-specific files (\config\_linux.go\, \config\_freebsd.go\, \namespaces\_linux.go\, etc.) to separate Linux and FreeBSD implementation details. This change introduces a common \ParseDevice\ function for parsing device specifications and adds support for Container Device Interface (CDI) devices on both platforms. It also refactors namespace configuration to properly handle host, private, and shared modes for PID, IPC, UTS, User, Cgroup, and Network namespaces, including specific logic for pod infra container inheritance and rootless user namespace constraints.
pkg/specgen/generate · high confidence
Refactored version handling to reduce binary size and standardize API versioning
The version management logic has been restructured to introduce a raw version constant in a separate package, preventing semver parsing libraries from bloating the binary size. The main version package now uses this raw string to parse the semantic version and explicitly defines the supported API levels for both Libpod and Compat endpoint trees, ensuring clients can correctly negotiate API versions.
version · high confidence
Reorganized trust policy handling with new policy.json and registries.d support
The trust policy logic has been restructured into dedicated files (policy.go, registries.go, trust.go) to improve maintainability and add new capabilities. The system now supports the \sigstoreSigned\ trust type for both setting and displaying policies, and the \podman image trust show\ command now displays GPG key IDs and signature store locations for \signedBy\ entries. Additionally, the codebase has been modernized to use Go 1.20+ features (such as \maps\ and \slices\ packages) and switched to \sigs.k8s.io/yaml\ for YAML parsing, while preserving unknown fields in policy files to ensure forward compatibility.
pkg/trust · high confidence
Rootless port forwarding now uses RootlessKit v2 with dual-stack socket support
The rootlessport command has been rewritten to integrate with RootlessKit v2, replacing the previous implementation. This change improves memory efficiency and ensures correct handling of dual-stack sockets (IPv4/IPv6), while removing legacy Windows/WSL workarounds that are no longer needed. Users benefit from more reliable port mapping in rootless containers, particularly on systems requiring dual-stack network support.
cmd/rootlessport · high confidence
Secure user and group lookup with ID fallback
The \pkg/lookup\ package now resolves container user and group information using \filepath-securejoin\ to prevent symlink attacks when accessing \/etc/passwd\ and \/etc/group\. It also switches to the \moby/sys/user\ library for parsing these files. A key behavioral change is that when looking up a user or group by numeric ID, the system now returns a partial structure containing only that ID (along with the \ErrNoPasswdEntries\ or \ErrNoGroupEntries\ error) if the entry is not found, rather than failing completely or returning nil. This allows callers to proceed with numeric IDs even when the corresponding name is missing from the container's files.
pkg/lookup · high confidence
Support for host-gateway and improved URL validation in CLI arguments
The CLI now supports the special 'host-gateway' value in the --add-host flag, allowing users to reference the host's gateway IP directly. Additionally, URL validation for flags has been tightened to strictly require http or https schemes and a present host, rejecting paths like Windows drive letters (e.g., C:/hello/world) or URLs with unsupported schemes. The system also now correctly handles colons in Windows file paths for label and environment variable parsing, while maintaining stricter validation for non-Windows platforms.
cmd/podman/parse · high confidence
Support for optional mount type in --mount flag
The \--mount\ flag now allows users to omit the \type\ parameter; when unspecified, the system defaults to \volume\. This change is implemented via a new \FindMountType\ utility in \pkg/specgenutilexternal\ that parses mount specifications, extracting the type and remaining options while handling edge cases like non-key=value tokens and multiple type declarations.
pkg/specgenutilexternal · high confidence
Swagger API documentation models refactored to use Moby types and new Podman entities
The Swagger API definition files have been restructured to align with the switch to the moby/moby library. Error response models now embed the standard errorhandling.ErrorModel, and request models for network operations (create, connect, disconnect, update) and container updates are defined using types from github.com/moby/moby/api/types and Podman's entities package. Response models have been updated to reflect these changes, including specific responses for image SCP, system checks, and quadlet file access, ensuring the generated API documentation accurately reflects the current payload structures.
pkg/api/handlers/swagger · high confidence
Switch default database backend from BoltDB to SQLite
Podman now uses SQLite as the default storage backend for container and pod state, replacing the previous BoltDB implementation. This change improves concurrency and performance for state operations, though it requires a migration of existing state data from the old format to the new SQLite database.
libpod · high confidence
Timeout added to Hyper-V vsock readiness wait
The \podman machine init\ and \start\ commands on Windows now include a 90-second timeout when waiting for the guest VM to signal readiness over the hvsock connection. Previously, if the guest remained alive but failed to connect (due to a stuck boot, corrupted image, or ignition hang), the host command would hang indefinitely. This change ensures the operation fails gracefully after the timeout period rather than blocking forever.
pkg/machine/hyperv/vsock · high confidence
Unified inspect command with expanded resource support and report-based formatting
The \podman inspect\ command has been refactored to support inspecting a wider variety of resources, including pods, volumes, networks, and artifacts, in addition to the existing containers and images. The output formatting engine has been switched to use the \report.Formatter\ from the common package, allowing for consistent Go template-based output via the \--format\ flag while retaining JSON as the default. This change also introduces specific validation logic to prevent incompatible flag combinations, such as using \--size\ with images or pods, and ensures that the \--latest\ flag defaults to container inspection when used with \--type=all\.
cmd/podman/inspect · high confidence
Unified runtime initialization with TLS and remote connection support
The \pkg/domain/infra\ package now centralizes connection and runtime creation logic. A new \newConnectionWithoutLock\ helper in \runtime.go\ establishes client connections using explicit TLS certificate, key, and CA file paths from the configuration, supporting both local and remote modes. Platform-specific factories (\runtime\_abi.go\ for local Linux/FreeBSD and \runtime\_tunnel.go\ for remote/macOS) now route to either the local libpod runtime or the tunnel-based remote engine based on the configured \EngineMode\. The local runtime initialization (\runtime\_libpod.go\) has been expanded to support a wider range of command-line flags, including user namespace mapping, storage options, pull options, and network configuration directories.
pkg/domain/infra · high confidence
Updated Fish shell completion scripts for podman and podman-remote
The Fish shell completion scripts for both \podman\ and \podman-remote\ have been regenerated to align with newer versions of the Cobra library. This update ensures that command-line completions function correctly, including specific fixes for issues where commands prefixed with a space might fail, and improves handling of flag completions and directive parsing within the Fish environment.
completions/fish · high confidence
Updated systemd unit files for Podman service management
The systemd unit files in contrib/systemd/system have been updated to improve compatibility and reliability. The podman.service now explicitly references the podman-system-service documentation and uses the installed podman binary path. The podman-restart.service has been fixed to correctly handle the 'unless-stopped' restart policy by adding an ExecStop command and ensuring it works even when no containers are present. A new podman-kube@.service template replaces the old podman-play-kube unit, utilizing the 'podman kube' command structure. Additionally, new units have been introduced: podman-auto-update.service and .timer for scheduled image updates, and podman-clean-transient.service to clean up leftover state from transient storage modes after unclean boots. The podman-docker.conf file now creates a symlink from docker.sock to podman.sock for Docker compatibility.
contrib/systemd/system · high confidence
Updated vendor library for safer network namespace handling in Go
The vendored \containernetworking/plugins/pkg/ns\ library has been updated, introducing stricter requirements for managing network namespaces within Go processes. The new version includes documentation and code changes that emphasize the risks of goroutine thread-switching and mandates the use of \runtime.LockOSThread()\ or the \ns.Do()\ wrapper to ensure network namespace operations remain stable. This change affects how the system interacts with Linux network namespaces, requiring callers to explicitly manage thread affinity to prevent unexpected namespace switches during long-lived, multithreaded operations.
vendor/github.com/containernetworking/plugins/pkg · high confidence
User systemd units now symlink to system-level definitions with new network wait service
The user-level systemd unit files in the contrib directory have been converted from standalone copies to symlinks pointing to their counterparts in the system-level directory, ensuring that user services stay in sync with system updates. Additionally, a new \podman-user-wait-network-online.service\ has been added to allow user services to reliably wait for the system network to come online before starting, addressing potential race conditions during boot.
contrib/systemd/user · high confidence
Windows machine commands can now request elevation via UAC
The Windows machine package now includes utilities to detect administrator privileges and relaunch the process with elevated rights. When running the \init\ or \rm\ commands, the system will automatically prompt the user for UAC approval if the current process lacks admin rights, ensuring these operations succeed without requiring manual manual elevation.
pkg/machine/windows · high confidence
macOS installer now configures PATH and man pages automatically
The macOS package installer now automatically adds /opt/podman/bin to the system PATH via /etc/paths.d and configures man page access by creating a manpath configuration file. The installation process also ensures the necessary directories exist and removes any previous /opt/podman installation before proceeding. The podman-mac-helper installation is attempted but errors are ignored to prevent installation failure.
contrib/pkginstaller/scripts · high confidence
Fixes
Fix Windows terminal color support by enabling virtual terminal processing
The terminal package now explicitly configures Windows console handles to enable virtual terminal processing, allowing proper color output and handling. This change introduces platform-specific implementations: a no-op for Unix systems and a Windows-specific function that sets the ENABLE\_VIRTUAL\_TERMINAL\_PROCESSING flag on standard input, output, and error handles. This resolves issues where remote breaks and other terminal interactions failed due to missing color support or incorrect console modes on Windows.
pkg/terminal · high confidence
Test coverage
3 commits adding/updating tests in test/e2e/sign; Add BATS test template for system tests; Add buildah bud test suite under podman; Add internal testing engine for system tests; Add testvol volume plugin for testing volume plugin functionality; Added Docker API compatibility test suite; Added Go bindings API tests for Podman v6; Added Linux-specific seccomp support test; Added Python REST API v2 test suite; Added TMT system tests for local and remote Podman scenarios; Added build test fixtures for volume preservation, scratch images, and preprocessing; Added e2e test configuration files for containers.conf settings; Added end-to-end tests for podman farm build and list commands; Added regression tests for Compose environment variables, volumes, and port mapping; Added test certificate assets and generation instructions; Added test fixtures for build tests; Added test for CDI device injection in Compose; Added test for Docker API network alias resolution with /etc/hosts; Added test for container mount and label configuration; Added test for default connection behavior in compose up; Added test for disabling healthchecks in Docker Compose; Added test for multi-network container connectivity; Added test for pasta network MTU configuration; Added test for simple port mapping in Docker Compose; Added test infrastructure configuration and documentation; Added test infrastructure for docker-compose v2; Added test utility to print the current version string; Added tests for Docker Compose network MTU and interface configuration; Added tests for IPAM static IP and MacAddress assignment in Compose; Added unit tests for test infrastructure utilities; Added upgrade testing infrastructure for Podman; E2E test suite modernization and stability improvements; Expanded e2e test coverage for Quadlet unit types and configuration keys; Initial APIv2 test suite for Podman REST API; Migrate Python APIv2 tests to pytest; New Python APIv2 test fixtures for OCI artifact support; Vendor test tool dependencies; Vendor test tool dependencies in test/tools/vendor.
Dependencies
Routine dependency updates across Go and Python ecosystems
This release includes a broad set of dependency updates across the project's Go and Python manifests. Go dependencies have been bumped, including significant version jumps for the containers ecosystem libraries (common, image, storage, buildah), the Docker client library, and various golang.org/x modules. Python dependencies have also been updated, notably upgrading setuptools to version 80.7.1 and pytest to version 8.4.0.
(dependencies) · high confidence
Updated vendor dependencies for containers/common, containers/image, and containers/storage
The vendored copies of the core container libraries (containers/common, containers/image, and containers/storage) have been updated to their latest versions. This brings in upstream improvements and fixes from the container-libs ecosystem, ensuring Podman uses the most recent implementations for image handling, storage management, and common utilities.
vendor · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 62 → 69 (+6.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 45 → 66 (+21.5)
- Architecture 100 → 91 (-9.2)
- Maturity 81 → 81 (+0.0)
- Readiness 97 → 90 (-6.4)
- Security 65 → 61 (-4.3)
Resolved (242)
- ConmonOCIRuntime.createRootlessContainer (cognitive 51) (libpod/oci_conmon_linux.go)
- ConmonOCIRuntime.createRootlessContainer (cyclomatic 25) (libpod/oci_conmon_linux.go)
- ConmonOCIRuntime.moveConmonToCgroupAndSignal (cognitive 22) (libpod/oci_conmon_linux.go)
- Container.addRootPropagation (cognitive 19) (libpod/container_internal_linux.go)
- Container.addSharedNamespaces (cognitive 47) (libpod/container_internal_linux.go)
- Container.addSharedNamespaces (cyclomatic 31) (libpod/container_internal_linux.go)
- Container.inspectJoinedNetworkNS (cognitive 30) (libpod/networking_linux.go)
- Container.inspectJoinedNetworkNS (cyclomatic 16) (libpod/networking_linux.go)
- Container.platformInspectContainerHostConfig (cognitive 185) (libpod/container_inspect_linux.go)
- Container.platformInspectContainerHostConfig (cyclomatic 69) (libpod/container_inspect_linux.go)
- ContainerEngine.SetupRootless (cognitive 44) (pkg/domain/infra/abi/system_linux.go)
- ContainerEngine.SetupRootless (cyclomatic 25) (pkg/domain/infra/abi/system_linux.go)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (cmd/podman/artifact/push.go)
- Duplicated block (10 lines × 2) (cmd/podman/common/completion.go)
- Duplicated block (10 lines × 2) (cmd/podman/common/completion.go)
- Duplicated block (10 lines × 2) (cmd/podman/containers/rm.go)
- Duplicated block (10 lines × 2) (libpod/boltdb_state.go)
- Duplicated block (10 lines × 2) (libpod/container_api.go)
- …and 222 more
New (754)
- CI installs an unverified third-party binary (.github/workflows/ci.yml)
- CI runs a third-party container image from a mutable tag (.github/workflows/ci.yml)
- Change coupling: types.go ↔ images.go (pkg/bindings/images/types.go)
- Container.Top (cognitive 17) (libpod/container_top_linux.go)
- Container.exec (cyclomatic 16) (libpod/container_exec.go)
- Container.readFromJournal (cognitive 62) (libpod/container_log_unsupported.go)
- Container.readFromJournal (cyclomatic 42) (libpod/container_log_unsupported.go)
- Container.waitForHealthy (cognitive 24) (libpod/container_internal.go)
- ContainerEngine.NetworkInspect (cognitive 19) (pkg/domain/infra/abi/network.go)
- Dependency pinned to a stale untagged commit: github.com/google/shlex
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Duplicated block (10 lines × 2) (cmd/podman/artifact/pull.go)
- Duplicated block (10 lines × 2) (cmd/podman/containers/pause.go)
- Duplicated block (10 lines × 2) (cmd/podman/images/import.go)
- Duplicated block (10 lines × 2) (libpod/boltdb_state.go)
- Duplicated block (10 lines × 2) (libpod/boltdb_state.go)
- Duplicated block (10 lines × 2) (libpod/container_exec.go)
- Duplicated block (10 lines × 2) (libpod/container_internal_freebsd.go)
- Duplicated block (10 lines × 2) (libpod/pod.go)
- …and 734 more
Changes since last survey
- 300 commits — 241 feature/other, 59 fixes
By area
- (repo) — 131 commits
- pkg/machine — 21 commits
- pkg/api — 17 commits
- (root) — 16 commits
- .github/workflows — 13 commits
- docs/source — 13 commits
- pkg/domain — 11 commits
- cmd/podman — 10 commits
- vendor/github.com — 10 commits
- test/e2e — 9 commits
- pkg/bindings — 8 commits
- test/system — 5 commits
- hack/ci — 4 commits
- libpod/container_internal_common.go — 3 commits
- test/apiv2 — 3 commits
- cmd/rootlessport — 2 commits
- libpod/container_internal.go — 2 commits
- pkg/systemd — 2 commits
- pkg/util — 2 commits
- test/utils — 2 commits
Notable commits
- fix: Fix ErrorToStringArray handling of empty stderr output
- fix: Fix health-startup-cmd behaviour when the value is not set
- fix: Fix list markup in Markdown
- fix: Fix machine init failure with read-only disk image
- fix: Merge pull request #28447 from jude-ruben/fix/machine-image-permissions
- fix: Merge pull request #28633 from aayushbaluni/fix/28378-iprange-compat-api
- fix: Merge pull request #29303 from virzak/fix/compat-info-rootless-cgroup-driver
- fix: Merge pull request #29343 from sudo-muneeb/fix-apple-leak-clean
- fix: Merge pull request #29388 from AftAb-25/fix/events-network-filter
- fix: Merge pull request #29468 from JamesBalazs/healthcheck-fix
- fix: Merge pull request #29482 from rjgoyln/fix/ci-log-summary-parser
- fix: Merge pull request #29528 from vtushar06/fix-apiv2-exit-status
- fix: Merge pull request #29534 from Atishyy27/fix/error-to-string-array-empty-output
- fix: Merge pull request #29565 from magic-peach/fix-29555-kube-memory-emptydir-shared
- fix: Merge pull request #29566 from i-OmSharma/fix-ulimit-memlock-units
- fix: Merge pull request #29587 from haneul-24/fix/kube-play-nested-image-path
- fix: Merge pull request #29588 from ROKUMATE/fix-bindings-generator-trimsuffix
- fix: Merge pull request #29589 from rsvr76/fix-28452-clean
- fix: Merge pull request #29590 from prabhat-kumar96/fix-windows-hyperv-9p-detach
- fix: Merge pull request #29594 from CodeWithAK28/fix-swagger-check-subrouters
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
podman-container-tools/podman was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6e9418497e8713fc2170d94200ca85591b64c9a0 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.